Skip to content

docs(patch-policy): cosign verify names a tag that exists — X.Y.Z, not vX.Y.Z - #182

Merged
MrChengLen merged 1 commit into
mainfrom
pr-patch-policy-image-tag
Sep 30, 2026
Merged

MrChengLen merged 1 commit into
mainfrom
pr-patch-policy-image-tag

Conversation

@MrChengLen

Copy link
Copy Markdown
Owner

What

docs/patch-policy.md → Signing & verification: the cosign verify example named the image tag vX.Y.Z. docker.yml tags release images via metadata-action type=semver,pattern={{version}} (and {{major}}.{{minor}}), which drops the Git tag's v: release v1.2.3 pushes 1.2.3, 1.2, 1.2.3-office and 1.2-office. The documented command therefore failed for every release. It now says X.Y.Z, like the filemorph:1.2.3 in docs/release-signing.md.

Live check against GHCR (anonymous registry API): filemorph:1.1.0 → 200, filemorph:v1.1.0 → 404. None of the 570 published tags starts with v.

Guard

  • tests/test_supply_chain_hygiene.py::test_docs_name_no_v_prefixed_image_tag fails when a tracked top-level or docs/ Markdown file (CHANGELOG aside) names a filemorph:v… image tag, with or without the ghcr.io/mrchenglen/ prefix. It fails against the old text (naming docs/patch-policy.md:109) and passes after the fix.
  • It matches any v, not only v<digit>: this bug used the placeholder vX.Y.Z, which a digit-only pattern would miss.
  • With the docs fixed the guard never meets a hit, so test_v_image_tag_pattern_recognises_any_v_tag pins the pattern (same approach as test_privileged_recognises_secrets_in_any_form). Four narrowed or widened variants of the pattern each fail it.
  • The git ls-files doc listing moves into _tracked_docs(), shared with the existing pip-audit docs guard, which behaves as before.
  • Known limit: a DSN example with a password starting with v (postgresql://filemorph:v…@) would trip it. The docs mask that password as *** today.

Deliberately not changed

The --certificate-identity-regexp flags stay as they are. Pinning the identity to the tag build is separate work that has not landed yet; this PR touches only the tag, so the overlap with that work is one line.

Verification

  • Full suite: 1488 passed, 72 skipped (local Windows run; WeasyPrint/pikepdf tests skip there)
  • ruff check + ruff format --check: clean
  • gitleaks on the staged diff, the pre-commit scope-guard and scripts/scope_review.py: clean
  • commit-review gate: security-auditor PASS (no Critical/High/Medium); code-reviewer approve (no Critical/Warning). Two of its optional suggestions are applied: the pattern self-test and a more precise CHANGELOG sentence.

🤖 Generated with Claude Code

…t vX.Y.Z

docker.yml tags release images with metadata-action's semver patterns,
which drop the Git tag's `v`: release v1.2.3 pushes the version tags
1.2.3, 1.2, 1.2.3-office and 1.2-office. The "Signing & verification"
example in docs/patch-policy.md verified
`ghcr.io/mrchenglen/filemorph:vX.Y.Z`, a tag that never exists (GHCR:
1.1.0 resolves, v1.1.0 is 404), so the command failed for every release.
docs/release-signing.md already used the right form. The identity flags
stay as they are; tightening them is separate work.

Guard: test_docs_name_no_v_prefixed_image_tag fails when a tracked
top-level or docs/ Markdown file names a `filemorph:v…` image tag, with or
without the registry path in front. It matches any `v` after `filemorph:`,
not only a digit: the bug used the placeholder vX.Y.Z, which a digit-only
pattern would miss. Run against the old text, it names
docs/patch-policy.md:109. With the docs fixed it never meets a hit, so a
parametrised self-test pins the pattern: it catches the placeholder, a
version and the short name, and leaves Git refs and the SBOM file name
alone (four narrowed or widened variants of the pattern each fail it). The
tracked-docs listing moves into _tracked_docs(), shared with the pip-audit
docs guard, which behaves as before.

Full suite 1488 green (72 skipped); ruff, gitleaks and scope-guard clean.
No templates or dependencies touched, so i18n-drift and pip-audit do not
apply.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen
MrChengLen merged commit 7c4a46c into main Sep 30, 2026
7 checks passed
@MrChengLen
MrChengLen deleted the pr-patch-policy-image-tag branch September 30, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant