mirror of
https://github.com/whyour/qinglong.git
synced 2026-09-28 09:02:12 +08:00
fix: pin Debian Python 3.10 base for full release matrix
This commit is contained in:
@@ -474,7 +474,7 @@ jobs:
|
|||||||
|
|
||||||
publish:
|
publish:
|
||||||
if: ${{ github.repository == 'whyour/qinglong' && github.ref == 'refs/heads/master' }}
|
if: ${{ github.repository == 'whyour/qinglong' && github.ref == 'refs/heads/master' }}
|
||||||
needs: [build-alpine, build-debian]
|
needs: [build-alpine, build-debian, build-alpine310, build-debian310]
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
@@ -504,4 +504,17 @@ jobs:
|
|||||||
package-manager-cache: false
|
package-manager-cache: false
|
||||||
|
|
||||||
- name: Publish npm package with OIDC
|
- name: Publish npm package with OIDC
|
||||||
run: npm publish --access public --registry=https://registry.npmjs.org
|
shell: bash
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
name=$(node -p 'require("./package.json").name')
|
||||||
|
version=$(node -p 'require("./package.json").version')
|
||||||
|
if npm view "$name@$version" version --json --registry=https://registry.npmjs.org > "$RUNNER_TEMP/npm-version.json" 2> "$RUNNER_TEMP/npm-version-error.log"; then
|
||||||
|
jq -e --arg version "$version" '. == $version' "$RUNNER_TEMP/npm-version.json" > /dev/null
|
||||||
|
echo "::notice::$name@$version is already published; skipping npm publication for this image rebuild."
|
||||||
|
elif jq -e '.error.code == "E404"' "$RUNNER_TEMP/npm-version.json" > /dev/null; then
|
||||||
|
npm publish --access public --registry=https://registry.npmjs.org
|
||||||
|
else
|
||||||
|
echo '::error::Could not check the published npm version; refusing to publish.'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|||||||
@@ -2,7 +2,9 @@
|
|||||||
# full Debian build matrix, including arm/v7, ppc64le, and s390x.
|
# full Debian build matrix, including arm/v7, ppc64le, and s390x.
|
||||||
FROM node:20-bookworm-slim AS nodebuilder
|
FROM node:20-bookworm-slim AS nodebuilder
|
||||||
|
|
||||||
FROM python:3.10-slim-bookworm AS builder
|
# Keep the full release matrix, including s390x, on the same immutable base.
|
||||||
|
# The floating 3.10-slim-bookworm tag no longer includes s390x.
|
||||||
|
FROM python:3.10.19-slim-bookworm@sha256:23f63358922e79a794f71be8f3723c84e5ccca9638af3f74456dc73d6184499e AS builder
|
||||||
COPY package.json .npmrc pnpm-lock.yaml /tmp/build/
|
COPY package.json .npmrc pnpm-lock.yaml /tmp/build/
|
||||||
COPY --from=nodebuilder /usr/local/bin/node /usr/local/bin/
|
COPY --from=nodebuilder /usr/local/bin/node /usr/local/bin/
|
||||||
COPY --from=nodebuilder /usr/local/lib/node_modules/. /usr/local/lib/node_modules/
|
COPY --from=nodebuilder /usr/local/lib/node_modules/. /usr/local/lib/node_modules/
|
||||||
@@ -14,7 +16,7 @@ RUN set -x && \
|
|||||||
cd /tmp/build && \
|
cd /tmp/build && \
|
||||||
pnpm install --prod --frozen-lockfile
|
pnpm install --prod --frozen-lockfile
|
||||||
|
|
||||||
FROM python:3.10-slim-bookworm
|
FROM python:3.10.19-slim-bookworm@sha256:23f63358922e79a794f71be8f3723c84e5ccca9638af3f74456dc73d6184499e
|
||||||
|
|
||||||
ARG QL_MAINTAINER="whyour"
|
ARG QL_MAINTAINER="whyour"
|
||||||
LABEL maintainer="${QL_MAINTAINER}"
|
LABEL maintainer="${QL_MAINTAINER}"
|
||||||
|
|||||||
@@ -0,0 +1,70 @@
|
|||||||
|
const assert = require('node:assert/strict');
|
||||||
|
const test = require('node:test');
|
||||||
|
const fs = require('node:fs');
|
||||||
|
const os = require('node:os');
|
||||||
|
const path = require('node:path');
|
||||||
|
const { spawnSync } = require('node:child_process');
|
||||||
|
const yaml = require('js-yaml');
|
||||||
|
const workflow = yaml.load(
|
||||||
|
fs.readFileSync('.github/workflows/build-docker-image.yml', 'utf8'),
|
||||||
|
);
|
||||||
|
const publication = workflow.jobs.publish.steps.find(
|
||||||
|
(step) => step.name === 'Publish npm package with OIDC',
|
||||||
|
).run;
|
||||||
|
|
||||||
|
test('npm publication waits for every release image, including Python 3.10', () => {
|
||||||
|
for (const name of [
|
||||||
|
'build-alpine',
|
||||||
|
'build-debian',
|
||||||
|
'build-alpine310',
|
||||||
|
'build-debian310',
|
||||||
|
])
|
||||||
|
assert.ok(workflow.jobs.publish.needs.includes(name), name);
|
||||||
|
});
|
||||||
|
|
||||||
|
for (const [scenario, expectedStatus, published] of [
|
||||||
|
['existing', 0, false],
|
||||||
|
['missing', 0, true],
|
||||||
|
['unauthorized', 1, false],
|
||||||
|
['network', 1, false],
|
||||||
|
['unexpected-version', 1, false],
|
||||||
|
]) {
|
||||||
|
test(`npm publication handles ${scenario} without publishing an unverified version`, (t) => {
|
||||||
|
const root = fs.mkdtempSync(path.join(os.tmpdir(), 'ql-npm-publication-'));
|
||||||
|
t.after(() => fs.rmSync(root, { recursive: true, force: true }));
|
||||||
|
const bin = path.join(root, 'bin');
|
||||||
|
fs.mkdirSync(bin);
|
||||||
|
fs.writeFileSync(
|
||||||
|
path.join(root, 'package.json'),
|
||||||
|
JSON.stringify({ name: '@fixture/qinglong', version: '2.22.0' }),
|
||||||
|
);
|
||||||
|
fs.writeFileSync(
|
||||||
|
path.join(bin, 'npm'),
|
||||||
|
`#!/usr/bin/env node
|
||||||
|
const fs = require('node:fs');
|
||||||
|
if (process.argv[2] === 'publish') { fs.writeFileSync('published', 'yes'); process.exit(0); }
|
||||||
|
if (process.argv[2] !== 'view') process.exit(99);
|
||||||
|
switch (process.env.QL_PUBLISH_SCENARIO) {
|
||||||
|
case 'existing': console.log(JSON.stringify('2.22.0')); break;
|
||||||
|
case 'unexpected-version': console.log(JSON.stringify('2.21.0')); break;
|
||||||
|
case 'missing': console.log(JSON.stringify({error:{code:'E404'}})); process.exit(1);
|
||||||
|
case 'unauthorized': console.log(JSON.stringify({error:{code:'E401'}})); process.exit(1);
|
||||||
|
case 'network': console.log('upstream unavailable'); process.exit(1);
|
||||||
|
}
|
||||||
|
`,
|
||||||
|
{ mode: 0o755 },
|
||||||
|
);
|
||||||
|
const result = spawnSync('bash', ['-c', publication], {
|
||||||
|
cwd: root,
|
||||||
|
encoding: 'utf8',
|
||||||
|
env: {
|
||||||
|
...process.env,
|
||||||
|
PATH: `${bin}${path.delimiter}${process.env.PATH}`,
|
||||||
|
RUNNER_TEMP: root,
|
||||||
|
QL_PUBLISH_SCENARIO: scenario,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
assert.equal(result.status, expectedStatus, result.stdout + result.stderr);
|
||||||
|
assert.equal(fs.existsSync(path.join(root, 'published')), published);
|
||||||
|
});
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user