docs(patch-policy): cosign verify names a tag that exists — X.Y.Z, not vX.Y.Z - #182
Merged
Merged
Conversation
…t vX.Y.Z docker.yml tags release images with metadata-action's semver patterns, which drop the Git tag's `v`: release v1.2.3 pushes the version tags 1.2.3, 1.2, 1.2.3-office and 1.2-office. The "Signing & verification" example in docs/patch-policy.md verified `ghcr.io/mrchenglen/filemorph:vX.Y.Z`, a tag that never exists (GHCR: 1.1.0 resolves, v1.1.0 is 404), so the command failed for every release. docs/release-signing.md already used the right form. The identity flags stay as they are; tightening them is separate work. Guard: test_docs_name_no_v_prefixed_image_tag fails when a tracked top-level or docs/ Markdown file names a `filemorph:v…` image tag, with or without the registry path in front. It matches any `v` after `filemorph:`, not only a digit: the bug used the placeholder vX.Y.Z, which a digit-only pattern would miss. Run against the old text, it names docs/patch-policy.md:109. With the docs fixed it never meets a hit, so a parametrised self-test pins the pattern: it catches the placeholder, a version and the short name, and leaves Git refs and the SBOM file name alone (four narrowed or widened variants of the pattern each fail it). The tracked-docs listing moves into _tracked_docs(), shared with the pip-audit docs guard, which behaves as before. Full suite 1488 green (72 skipped); ruff, gitleaks and scope-guard clean. No templates or dependencies touched, so i18n-drift and pip-audit do not apply. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
docs/patch-policy.md→ Signing & verification: thecosign verifyexample named the image tagvX.Y.Z.docker.ymltags release images via metadata-actiontype=semver,pattern={{version}}(and{{major}}.{{minor}}), which drops the Git tag'sv: releasev1.2.3pushes1.2.3,1.2,1.2.3-officeand1.2-office. The documented command therefore failed for every release. It now saysX.Y.Z, like thefilemorph:1.2.3indocs/release-signing.md.Live check against GHCR (anonymous registry API):
filemorph:1.1.0→ 200,filemorph:v1.1.0→ 404. None of the 570 published tags starts withv.Guard
tests/test_supply_chain_hygiene.py::test_docs_name_no_v_prefixed_image_tagfails when a tracked top-level ordocs/Markdown file (CHANGELOG aside) names afilemorph:v…image tag, with or without theghcr.io/mrchenglen/prefix. It fails against the old text (namingdocs/patch-policy.md:109) and passes after the fix.v, not onlyv<digit>: this bug used the placeholdervX.Y.Z, which a digit-only pattern would miss.test_v_image_tag_pattern_recognises_any_v_tagpins the pattern (same approach astest_privileged_recognises_secrets_in_any_form). Four narrowed or widened variants of the pattern each fail it.git ls-filesdoc listing moves into_tracked_docs(), shared with the existing pip-audit docs guard, which behaves as before.v(postgresql://filemorph:v…@) would trip it. The docs mask that password as***today.Deliberately not changed
The
--certificate-identity-regexpflags stay as they are. Pinning the identity to the tag build is separate work that has not landed yet; this PR touches only the tag, so the overlap with that work is one line.Verification
ruff check+ruff format --check: cleanscripts/scope_review.py: clean🤖 Generated with Claude Code