Skip to content

Stop syncing the Docker Hub description from CI - #44

Open
RealDougEubanks wants to merge 1 commit into
mainfrom
fix/drop-dockerhub-description-sync
Open

RealDougEubanks wants to merge 1 commit into
mainfrom
fix/drop-dockerhub-description-sync

Conversation

@RealDougEubanks

Copy link
Copy Markdown
Owner

Why

peter-evans/dockerhub-description PATCHes the Docker Hub repository endpoint, and Docker Hub rejects that for a repo:write token.

Verified on solarham run 36191394041 after rotating to a repo:write credential:

docker/login-action        -> success
Build and push             -> success
Attest build provenance    -> success
Sync the Docker Hub description -> Sending PATCH request
                                -> ##[error]Forbidden

The image published fine. Only the cosmetic README sync failed.

The trade being refused

Making it work needs repo:admin. Docker Hub has no per-repository scoping for individual accounts, so repo:admin means Read, Write and Delete across every image repository on the account.

That would give CI runners the ability to destroy published images, in exchange for a README staying in sync. The old token had exactly that scope; this change is part of dropping it.

What replaces it

Update the Docker Hub page by hand when the text changes, or run the sync locally from an admin token that never enters CI. The source markdown is unchanged and still in the repo.

A comment at the removal site records the reasoning, so this does not get re-added and quietly require admin again.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SGfGnXm7Bc5MNgwyV4sjT4

peter-evans/dockerhub-description PATCHes the repository endpoint, which
Docker Hub rejects for a repo:write token. Verified on solarham run
36191394041: login and "Build and push" both succeeded, the image published
with provenance attested, and only this step returned "Forbidden".

Making it work requires repo:admin. Docker Hub has no per-repository scoping
for individual accounts, so repo:admin grants Read, Write and DELETE across
every image repository on the account. Giving CI the ability to destroy
published images so a README stays in sync is the wrong trade, and the point
of the credential rotation this accompanies was to remove exactly that.

The source markdown stays in the repo. Update the Docker Hub page by hand, or
locally with an admin token that never enters CI. A comment at the removal
site records why, so it is not re-added and silently made to need admin again.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SGfGnXm7Bc5MNgwyV4sjT4
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

  • .github/workflows/release.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant