Repository navigation
Conversation
…ace (RHDHBUGS-3635) Assisted-By: opencode Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
ca3e7a5 to
74b9cbc
Compare
Assisted-By: opencode Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
74b9cbc to
164415b
Compare
…ification - Write WORKSPACE_SKIPPED_UNCHANGED_SINCE=false to GITHUB_OUTPUT before exiting when skopeo is missing, so the action step captures the output even though the shell step runs with `|| true`; downstream steps then correctly treat the workspace as non-skipped instead of green-lighting a broken artifact. - Remove the stray reference to a `push-container-image` input in the action.yaml description for `last-publish-commit`; that flag is hardcoded in the step env, not an action input. - Correct the README claim that the script 'fails with an error' (true when invoked directly, not when called through the action) to describe the actual observable outcome via the action. - Add a README note explaining that a `versions.json` bump on a release branch causes all workspaces to be re-exported on the next run because the tag prefix changes; skopeo then finds no images under the new prefix and the skip is bypassed for all of them. Assisted-By: opencode rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
|
to validate this is working we should run it against the broken scorecard images? |
…ion test suite - Support multi-platform OCI image indexes and manifest lists in verify_registry_artifact by dereferencing child manifests when top-level annotations are not present. - Extract verification logic into export-dynamic/verify-registry-artifacts.sh following the pack-dist-dynamic pattern. - Add comprehensive test suite in export-dynamic/verify-registry-artifacts.test.sh and wire into test-pack-dist-dynamic workflow. Assisted-By: opencode Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
|
Great suggestion! We investigated this and tested against those images: Background & Quay vs GHCR
Updates in this PRWe updated the verification check ( Test ResultsTested against both Quay multi-arch images and GHCR single manifests:
We have also added an automated test suite ( |
…fact Merge collapsible if statements in verify-registry-artifacts.sh to resolve SonarCloud S1066. Assisted-By: opencode Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
|



Summary
Fixes RHDHBUGS-3635
When determining whether to skip a workspace because its last commit is an ancestor of the last published commit, verify that all expected container images for the workspace actually exist in the registry and contain valid, non-empty dynamic package metadata (
io.backstage.dynamic-packages).If any expected artifact is missing from the registry or has invalid/empty dynamic package metadata (such as from a cancelled publish or export failure), do not skip the workspace — proceed with exporting and publishing to self-heal the missing/broken artifact.