Skip to content

Add mise sandbox kit v3, MIT license, and kit build/validate/publish CI - #1

Merged
viqueen merged 2 commits into
mainfrom
feature/mise-sandbox-kit-v3
Sep 28, 2026
Merged

viqueen merged 2 commits into
mainfrom
feature/mise-sandbox-kit-v3

Conversation

@viqueen

@viqueen viqueen commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds kits/ as the home for Docker sandbox kits (v3 descriptor), with a first kit: a mixin that installs mise-en-place as a pinned, checksum-verified static binary via its own install script, and runs mise install on every boot so a workspace's own mise.toml (if any) is honored automatically.
  • Relicenses the repo as MIT (was an unedited Apache-2.0 template), matching the license kits/mise/mise.yaml declares for the bundled tool.
  • Adds CI: validate-kits.yml (PRs and non-main pushes — build + kit-tck validate, never pushes) and publish-kits.yml (push to main — same gate, then pushes to ghcr.io/<owner>/<repo>:<kit>-<version> and :<kit>), sharing their build/validate steps through a build-kit composite action.
  • Pins this repo's own dev tooling (kit-tck, yq) in a root mise.toml, installed via jdx/mise-action in CI — the same tool kits/mise ships into a sandbox is used to manage this repo's own tooling.

Test plan

  • docker buildx build validates the descriptor and enforces the version pin (re-checks mise --version after install)
  • kit-tck validate — 18/18 conformance checks pass
  • Ownership audit on the exported OCI layout — every layer entry 0/0
  • Real filesystem composition onto a bare Debian base, mise --version runs correctly
  • mise install from the repo root installs kit-tck and yq from mise.toml, and both resolve on PATH via mise activate
  • CI run on this PR (validate-kits.yml) — pending

🤖 Generated with Claude Code

viqueen and others added 2 commits September 28, 2026 15:43
Introduces kits/ as the home for Docker sandbox kits (v3 descriptor) and
adds the first one: a mixin that installs mise-en-place as a pinned,
checksum-verified static binary via its own install script, and runs
`mise install` on every boot so a workspace's own mise.toml (if any) is
honored automatically without the agent having to run it by hand.

Also switches the repo's LICENSE from the unedited Apache-2.0 template to
MIT, matching the license mise.yaml declares for the bundled tool.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Splits kit CI into validate-kits.yml (PRs and non-main pushes: build +
kit-tck, never pushes) and publish-kits.yml (push to main: same gate,
then push to ghcr.io), sharing their build-and-validate steps through a
new build-kit composite action rather than duplicating them.

kit-tck and yq are now pinned in a root mise.toml and installed via
jdx/mise-action instead of a hand-rolled go install / curl+checksum
step, so this repo's own dev tooling uses mise the same way kits/mise
lets a sandbox use it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@viqueen
viqueen merged commit 6a6148b into main Sep 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant