Skip to content

ci: bind dispatched image builds to the verified source commit - #246

Merged
sylphx-desk-studio[bot] merged 1 commit into
mainfrom
ci/verified-image-source
Oct 10, 2026
Merged

sylphx-desk-studio[bot] merged 1 commit into
mainfrom
ci/verified-image-source

Conversation

@sylphx-desk-studio

@sylphx-desk-studio sylphx-desk-studio Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Change

The reusable image lane accepts an optional source-sha. Checkout and SOURCE_SHA build evidence bind that exact commit; existing callers default to the triggering commit.

Why

Downstream image publication must follow the successful post-merge Verify marker without accidentally building a newer main tip that has not been verified. A dispatch on main keeps the existing publisher identity while supplying the verified source separately.

Verification

Remote build at 320949aeffc6ecd8d574cb7a138405df5aaf77ae: python3 -m unittest discover -s tests -p test_image_lane_tools.py passed all 32 tests.

Remote actionlint 1.7.12 exited 1 for the two existing job.workflow_sha context errors at lines 198 and 265 (unchanged from main, previously lines 191 and 258). No new lint finding was reported. The validation binary was removed afterward.

@sylphx-desk-services sylphx-desk-services Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkout and build evidence now use the supplied verified source commit together, while callers omitting the input retain the event commit. The source contract test covers both bindings, and the checks passed at this head. No blocking regression found.

@sylphx-desk-studio
sylphx-desk-studio Bot added this pull request to the merge queue Oct 10, 2026
Merged via the queue into main with commit 7d0772d Oct 10, 2026
6 checks passed
@sylphx-desk-studio
sylphx-desk-studio Bot deleted the ci/verified-image-source branch October 10, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant