Skip to content

image: task, git-lfs and buildkit pinned by content in versions.yaml - #85

Merged
aledbf merged 1 commit into
mainfrom
image/dev-tools-pinned
Oct 1, 2026
Merged

aledbf merged 1 commit into
mainfrom
image/dev-tools-pinned

Conversation

@aledbf

@aledbf aledbf commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

install-dev-tools.sh downloaded Task, git-lfs and BuildKit with an empty sha256, so sha256sum -c never ran, and the versions lived in ${X_VERSION:-…} defaults nothing set — outside versions.yaml and the gate.

  • three download entries in versions.yaml (task and git-lfs sums match the upstream checksum files)
  • image/Dockerfile takes them as ARGs and sets them as ENV; mkosi.conf Environment= passes them to the postinst scripts
  • the script requires each version and sum, and always verifies
  • isal pigz dropped from the script's apt-get: mkosi.conf already installs them
  • image.yml's hack/touches call lists the new entries

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

install-dev-tools.sh fetched all three with an empty sha256, so its check never ran, and their
versions sat in env defaults nothing set. They are versions.yaml entries now, handed in by
image/Dockerfile and passed through mkosi.conf's Environment=, and the script refuses to run
without a sum. isal and pigz were installed twice; mkosi.conf's Packages keeps them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aledbf
aledbf merged commit d960dbf into main Oct 1, 2026
9 of 10 checks passed
@aledbf
aledbf deleted the image/dev-tools-pinned branch October 1, 2026 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant