Skip to content

ci(supply-chain): pin Dockerfile base images + extend Rust CI to ha-main#1

Merged
agriev merged 1 commit into
ha-mainfrom
prod-hardening-s1
May 7, 2026
Merged

ci(supply-chain): pin Dockerfile base images + extend Rust CI to ha-main#1
agriev merged 1 commit into
ha-mainfrom
prod-hardening-s1

Conversation

@agriev

@agriev agriev commented May 7, 2026

Copy link
Copy Markdown
Owner

PR-S1 companion. Pins debian:bookworm-slim + cubejs/rust-builder by digest, fires rust-cubestore-master.yml on ha-main pushes, adds scripts/pin-base-images.sh refresh helper.

…CI to ha-main

Pin debian:bookworm-slim and cubejs/rust-builder:bookworm-llvm-18 by
sha256 digest so a tag rewrite upstream can't silently change what we
build. Add scripts/pin-base-images.sh as a tooled refresh path —
intentional roll-forward becomes a reviewable diff.

Also fire the Rust master workflow on ha-main pushes so the HA fork
catches Cargo.lock drift on every merge instead of only at the next
upstream sync.
@agriev agriev merged commit 27ba19f into ha-main May 7, 2026
26 of 28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant