5 Commits
Author SHA1 Message Date
austin dbe61a28ec Update dependency lucide-react to v1.28.0
renovate/artifacts Artifact file update failure
build-and-publish / build (pull_request) Successful in 2m19s
2026-07-30 09:01:48 +00:00
austin 7b27dd2264 Merge pull request 'A pull request must not touch :latest' (#12) from ci/pr-image-tag into main
build-and-publish / build (push) Successful in 2m17s
2026-07-27 09:58:25 -05:00
austinandClaude Opus 5 4f4082ecd7 A pull request must not touch :latest
build-and-publish / build (pull_request) Successful in 2m0s
This runner builds on the host's Docker daemon — the same daemon the live
container runs on — so retagging :latest IS a deployment. Watchtower compares
the running container's image against :latest, sees they differ, and recreates
the container from whatever was just built locally. Gating only the push was
never enough; the build itself was the deploy.

The worse failure is quieter. Reassigning :latest leaves the running
container's old image untagged, and once that image is pruned Watchtower can no
longer read it to compare against:

  Failed to retrieve container image info: No such image: sha256:…
  Unable to update container: no available image info.

bennett-portfolio hit exactly that. It sat on a four-day-old build, failing to
update 720 times in twenty-four hours, reporting healthy the whole time, and had
to be recreated by hand. This repo has the same workflow and the same exposure —
it simply has not been unlucky yet.

A PR now builds pr-<number>, which nothing watches. Trivy scans whatever was
built either way, so a bad Dockerfile or a new CVE still blocks the merge, and
the push step is unchanged — still main-only.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-07-27 09:53:24 -05:00
austin 77149e10a5 Merge pull request 'Update bennett platform to v0.1.10' (#11) from renovate/bennett-platform into main
build-and-publish / build (push) Successful in 1m46s
2026-07-26 21:59:39 -05:00
austin 7ddaf9eabe Update bennett platform to v0.1.10
build-and-publish / build (pull_request) Successful in 2m2s
2026-07-27 02:57:35 +00:00
3 changed files with 35 additions and 7 deletions
+32 -4
View File
@@ -40,7 +40,35 @@ jobs:
mvn -B -ntp -s .gitea/ci-settings.xml -DskipFrontend=true verify
# Build + Trivy on every run (PRs included), so a broken Dockerfile or a new HIGH/CRITICAL CVE
# blocks the merge. Only the push is main-only.
# blocks the merge.
#
# A PULL REQUEST MUST NOT TOUCH THE :latest TAG. This runner builds on the host's Docker daemon —
# the same daemon the live container runs on — so retagging :latest IS a deployment: Watchtower
# compares the running container's image against :latest, finds they differ, and recreates the
# container from the locally built image. Gating only the push is not enough; the build is the
# deploy.
#
# The damage is not only that unmerged code ships. Reassigning :latest leaves the running
# container's old image untagged, and once that image is pruned Watchtower can no longer read it
# to compare against, so it gives up every cycle:
#
# Failed to retrieve container image info: No such image: sha256:…
# Unable to update container "/<name>": no available image info.
#
# That happened to bennett-portfolio on 2026-07-27: it sat on a four-day-old build, failing to
# update 720 times in twenty-four hours, reporting healthy throughout. It had to be recreated by
# hand. This repo has the same workflow and the same exposure.
#
# So a PR builds pr-<number>, which nothing watches. Trivy scans whatever was built, and the push
# step below still only runs off a PR.
- name: Choose the image tag
run: |
if [ "${{ github.event_name }}" = "pull_request" ]; then
echo "IMAGE_TAG=pr-${{ github.event.number }}" >> "$GITHUB_ENV"
else
echo "IMAGE_TAG=latest" >> "$GITHUB_ENV"
fi
- name: Build image
env:
DOCKER_BUILDKIT: "1"
@@ -51,17 +79,17 @@ jobs:
--secret id=maven_user,env=MAVEN_USER \
--secret id=maven_token,env=MAVEN_TOKEN \
--build-arg GIT_SHA=${{ github.sha }} \
-t git.thebennett.net/reformedwitness/confessions-of-grace:latest -t git.thebennett.net/reformedwitness/confessions-of-grace:${{ github.sha }} .
-t "git.thebennett.net/reformedwitness/confessions-of-grace:$IMAGE_TAG" -t git.thebennett.net/reformedwitness/confessions-of-grace:${{ github.sha }} .
- name: Scan image (Trivy)
run: |
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
aquasec/trivy:latest image --scanners vuln --severity HIGH,CRITICAL --ignore-unfixed --no-progress \
git.thebennett.net/reformedwitness/confessions-of-grace:latest || true
"git.thebennett.net/reformedwitness/confessions-of-grace:$IMAGE_TAG" || true
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
aquasec/trivy:latest image --scanners vuln --severity HIGH,CRITICAL --ignore-unfixed \
--pkg-types library --exit-code 1 --no-progress \
git.thebennett.net/reformedwitness/confessions-of-grace:latest
"git.thebennett.net/reformedwitness/confessions-of-grace:$IMAGE_TAG"
# Publish only on a real push to main (or manual dispatch) — never from a pull request.
- name: Push image
+1 -1
View File
@@ -11,7 +11,7 @@
"dependencies": {
"clsx": "2.1.1",
"date-fns": "4.4.0",
"lucide-react": "1.26.0",
"lucide-react": "1.28.0",
"react": "^19.2.7",
"react-dom": "^19.2.7",
"react-router-dom": "7.18.1",
+2 -2
View File
@@ -7,7 +7,7 @@
<parent>
<groupId>net.thebennett.platform</groupId>
<artifactId>platform-parent</artifactId>
<version>0.1.9</version>
<version>0.1.10</version>
<relativePath/>
</parent>
@@ -26,7 +26,7 @@
<dependency>
<groupId>net.thebennett.platform</groupId>
<artifactId>platform-bom</artifactId>
<version>0.1.9</version>
<version>0.1.10</version>
<type>pom</type>
<scope>import</scope>
</dependency>