image pinning: eliminate :latest from all 5 unpinned templates + standing gate
bentopdf :latest -> v2.8.6; calibre-web :latest -> v4.0.6 (== running digest on demo 9201, c31a738b - pin is a no-op); papra :latest -> 26.6.1-rootless (latest was the rootless variant); recipe-importer :latest -> v0.9.11 (tag pre-existed, digest-equal, no retag needed); termix :latest -> 2.5.0. All five pins digest-identical to what :latest resolved to on 2026-07-12. New gate scripts/check-image-pins.py (catches floating tags AND untagged refs; red-proofed both shapes). Standing rule in CLAUDE.md + REUSE.md row.
This commit is contained in:
@@ -27,3 +27,7 @@ deployed `app.yaml` (customer secrets) is never overwritten. Full deploy details
|
||||
- Update `CHANGELOG.md` (newest on top) and overwrite `REPORT.md` with every pushed change.
|
||||
- No secrets in any committed file; secrets are generated at deploy time via `deploy_fields`
|
||||
`generate:` specs.
|
||||
- **Never `:latest` or untagged images in templates** — pin a concrete version tag; an app deployed
|
||||
anywhere in the fleet is pinned to the digest it is currently running (a pin must never cause a
|
||||
version jump). Digest pins (`@sha256:`) also count. Gate: `python scripts/check-image-pins.py`
|
||||
(run after any compose change; exit 1 on any floating/missing tag).
|
||||
|
||||
Reference in New Issue
Block a user