v1.0.1 — MIT license and usage documentation
Changes
- Add the MIT license, attributed to Syndicate LLC consistently with TechnicSolder, and declare it in package metadata.
- Add a README covering installation, token permissions, inputs/outputs, supported files, digest requirements, security boundaries, and development.
- Explain that publisher metadata can be coarse (for example,
24-alpine) and that unpinned tags cannot identify historical image contents. - No changes to action runtime behavior.
Verification
- 38 regression tests, lint, bundle rebuild, and Node24 CI passed.
- The README workflow and repository workflow examples passed actionlint; the README was rendered through GitHub Markdown.
- Tested production discovery and registry-comparison code against local PlatformAPI files: four definition files, four distinct pinned images (Node, MariaDB, Redis, OpenSearch), and four historical image-reference changes. The report identified MariaDB 12.3.2 → 12.3.3 and Redis 8.10.0 → 8.10.1. Interpolated production image references were explicitly skipped.
- Tested local TechnicSolder files: three definition files and eight literal references. Its historical Node 24.18.1-slim → 24.20.0-slim update was reported without guessing platform metadata, because neither reference has a digest pin.
- Neither consuming repository nor its pull requests was modified.
Usage
Copy examples/renovate.yml, or follow the README.
TechnicPack/docker-image-diff@v1 now points to this release. The immutable action reference is:
- uses: TechnicPack/docker-image-diff@a4b8adf7839c0c9ce110d235f771ffdc0b1fab05 # v1.0.1