ci: pin registry image to immutable SHA digest#16503
ci: pin registry image to immutable SHA digest#16503knative-prow[bot] merged 4 commits intoknative:mainfrom
Conversation
Using registry:2 without a minor-version pin pulls whatever is tagged :2 on Docker Hub at the time the job runs, breaking build reproducibility and potentially introducing unvetted changes. Pin to registry:2.8 which is the current stable minor series.
|
Hi @Ankitsinghsisodya. Thanks for your PR. I'm waiting for a knative member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
There was a problem hiding this comment.
Pull request overview
Pins the Docker image used for the local registry in the Kind e2e GitHub Actions workflow to improve CI reproducibility and avoid unexpected upstream changes.
Changes:
- Update the local registry container image from
registry:2toregistry:2.8in the Kind e2e workflow.
Comments suppressed due to low confidence (1)
.github/workflows/kind-e2e.yaml:60
- Typo in comment: “reigstry” should be “registry”.
# Make the $REGISTRY_NAME -> 127.0.0.1, to tell `ko` to publish to
# local reigstry, even when pushing $REGISTRY_NAME:$REGISTRY_PORT/some/image
sudo echo "127.0.0.1 $REGISTRY_NAME" | sudo tee -a /etc/hosts
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
/lgtm |
|
/ok-to-test |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #16503 +/- ##
==========================================
- Coverage 80.26% 80.15% -0.12%
==========================================
Files 217 217
Lines 13547 13547
==========================================
- Hits 10873 10858 -15
- Misses 2309 2321 +12
- Partials 365 368 +3 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
/retest |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Ankitsinghsisodya, dprotaso The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Fixes #16502
Changes
Pin the local Docker registry image to an immutable SHA digest in
kind-e2e.yaml.Using a mutable tag (
registry:2) pulls whatever Docker Hub resolves at job runtime, breaking reproducibility. This pins toregistry:3.0.0@sha256:6c5666b861f3505b116bb9aa9b25175e71210414bd010d92035ff64018f9457e, ensuring CI always pulls the exact same image.