Stop syncing the Docker Hub description from CI - #44
Open
RealDougEubanks wants to merge 1 commit into
Open
RealDougEubanks wants to merge 1 commit into
RealDougEubanks wants to merge 1 commit into
Conversation
peter-evans/dockerhub-description PATCHes the repository endpoint, which Docker Hub rejects for a repo:write token. Verified on solarham run 36191394041: login and "Build and push" both succeeded, the image published with provenance attested, and only this step returned "Forbidden". Making it work requires repo:admin. Docker Hub has no per-repository scoping for individual accounts, so repo:admin grants Read, Write and DELETE across every image repository on the account. Giving CI the ability to destroy published images so a README stays in sync is the wrong trade, and the point of the credential rotation this accompanies was to remove exactly that. The source markdown stays in the repo. Update the Docker Hub page by hand, or locally with an admin token that never enters CI. A comment at the removal site records why, so it is not re-added and silently made to need admin again. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SGfGnXm7Bc5MNgwyV4sjT4
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned Files
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
peter-evans/dockerhub-descriptionPATCHes the Docker Hub repository endpoint, and Docker Hub rejects that for arepo:writetoken.Verified on solarham run 36191394041 after rotating to a
repo:writecredential:The image published fine. Only the cosmetic README sync failed.
The trade being refused
Making it work needs
repo:admin. Docker Hub has no per-repository scoping for individual accounts, sorepo:adminmeans Read, Write and Delete across every image repository on the account.That would give CI runners the ability to destroy published images, in exchange for a README staying in sync. The old token had exactly that scope; this change is part of dropping it.
What replaces it
Update the Docker Hub page by hand when the text changes, or run the sync locally from an admin token that never enters CI. The source markdown is unchanged and still in the repo.
A comment at the removal site records the reasoning, so this does not get re-added and quietly require admin again.
🤖 Generated with Claude Code
https://claude.ai/code/session_01SGfGnXm7Bc5MNgwyV4sjT4