fix: pin Debian Python 3.10 base for full release matrix

This commit is contained in:
whyour
2026-09-26 01:40:39 +08:00
parent 6c487018c2
commit a67d44cde5
3 changed files with 89 additions and 4 deletions
+15 -2
View File
@@ -474,7 +474,7 @@ jobs:
publish:
if: ${{ github.repository == 'whyour/qinglong' && github.ref == 'refs/heads/master' }}
needs: [build-alpine, build-debian]
needs: [build-alpine, build-debian, build-alpine310, build-debian310]
runs-on: ubuntu-latest
permissions:
contents: read
@@ -504,4 +504,17 @@ jobs:
package-manager-cache: false
- name: Publish npm package with OIDC
run: npm publish --access public --registry=https://registry.npmjs.org
shell: bash
run: |
set -euo pipefail
name=$(node -p 'require("./package.json").name')
version=$(node -p 'require("./package.json").version')
if npm view "$name@$version" version --json --registry=https://registry.npmjs.org > "$RUNNER_TEMP/npm-version.json" 2> "$RUNNER_TEMP/npm-version-error.log"; then
jq -e --arg version "$version" '. == $version' "$RUNNER_TEMP/npm-version.json" > /dev/null
echo "::notice::$name@$version is already published; skipping npm publication for this image rebuild."
elif jq -e '.error.code == "E404"' "$RUNNER_TEMP/npm-version.json" > /dev/null; then
npm publish --access public --registry=https://registry.npmjs.org
else
echo '::error::Could not check the published npm version; refusing to publish.'
exit 1
fi
+4 -2
View File
@@ -2,7 +2,9 @@
# full Debian build matrix, including arm/v7, ppc64le, and s390x.
FROM node:20-bookworm-slim AS nodebuilder
FROM python:3.10-slim-bookworm AS builder
# Keep the full release matrix, including s390x, on the same immutable base.
# The floating 3.10-slim-bookworm tag no longer includes s390x.
FROM python:3.10.19-slim-bookworm@sha256:23f63358922e79a794f71be8f3723c84e5ccca9638af3f74456dc73d6184499e AS builder
COPY package.json .npmrc pnpm-lock.yaml /tmp/build/
COPY --from=nodebuilder /usr/local/bin/node /usr/local/bin/
COPY --from=nodebuilder /usr/local/lib/node_modules/. /usr/local/lib/node_modules/
@@ -14,7 +16,7 @@ RUN set -x && \
cd /tmp/build && \
pnpm install --prod --frozen-lockfile
FROM python:3.10-slim-bookworm
FROM python:3.10.19-slim-bookworm@sha256:23f63358922e79a794f71be8f3723c84e5ccca9638af3f74456dc73d6184499e
ARG QL_MAINTAINER="whyour"
LABEL maintainer="${QL_MAINTAINER}"
+70
View File
@@ -0,0 +1,70 @@
const assert = require('node:assert/strict');
const test = require('node:test');
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const { spawnSync } = require('node:child_process');
const yaml = require('js-yaml');
const workflow = yaml.load(
fs.readFileSync('.github/workflows/build-docker-image.yml', 'utf8'),
);
const publication = workflow.jobs.publish.steps.find(
(step) => step.name === 'Publish npm package with OIDC',
).run;
test('npm publication waits for every release image, including Python 3.10', () => {
for (const name of [
'build-alpine',
'build-debian',
'build-alpine310',
'build-debian310',
])
assert.ok(workflow.jobs.publish.needs.includes(name), name);
});
for (const [scenario, expectedStatus, published] of [
['existing', 0, false],
['missing', 0, true],
['unauthorized', 1, false],
['network', 1, false],
['unexpected-version', 1, false],
]) {
test(`npm publication handles ${scenario} without publishing an unverified version`, (t) => {
const root = fs.mkdtempSync(path.join(os.tmpdir(), 'ql-npm-publication-'));
t.after(() => fs.rmSync(root, { recursive: true, force: true }));
const bin = path.join(root, 'bin');
fs.mkdirSync(bin);
fs.writeFileSync(
path.join(root, 'package.json'),
JSON.stringify({ name: '@fixture/qinglong', version: '2.22.0' }),
);
fs.writeFileSync(
path.join(bin, 'npm'),
`#!/usr/bin/env node
const fs = require('node:fs');
if (process.argv[2] === 'publish') { fs.writeFileSync('published', 'yes'); process.exit(0); }
if (process.argv[2] !== 'view') process.exit(99);
switch (process.env.QL_PUBLISH_SCENARIO) {
case 'existing': console.log(JSON.stringify('2.22.0')); break;
case 'unexpected-version': console.log(JSON.stringify('2.21.0')); break;
case 'missing': console.log(JSON.stringify({error:{code:'E404'}})); process.exit(1);
case 'unauthorized': console.log(JSON.stringify({error:{code:'E401'}})); process.exit(1);
case 'network': console.log('upstream unavailable'); process.exit(1);
}
`,
{ mode: 0o755 },
);
const result = spawnSync('bash', ['-c', publication], {
cwd: root,
encoding: 'utf8',
env: {
...process.env,
PATH: `${bin}${path.delimiter}${process.env.PATH}`,
RUNNER_TEMP: root,
QL_PUBLISH_SCENARIO: scenario,
},
});
assert.equal(result.status, expectedStatus, result.stdout + result.stderr);
assert.equal(fs.existsSync(path.join(root, 'published')), published);
});
}