Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

chore: pin dogfood npm dependencies#17216

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
sreya merged 1 commit intomainfromjon/pinneddeps
Apr 2, 2025
Merged

chore: pin dogfood npm dependencies#17216

sreya merged 1 commit intomainfromjon/pinneddeps
Apr 2, 2025

Conversation

sreya
Copy link
Collaborator

No description provided.

Copy link
Member

@matifalimatifali left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Would these be taken care by dependabot updates after pining? Then yes.
Otherwise it may be a bit hectic to upgrade manually.

@sreya
Copy link
CollaboratorAuthor

sreya commentedApr 2, 2025
edited
Loading

@matifali why's that? It's pretty easy to get the hashes this doesn't change much about how we do things.

@matifali
Copy link
Member

Just because the person needs to get the sha manually from somewhere.

@sreya
Copy link
CollaboratorAuthor

If you're updating the Dockerfile you can just donpm view pkg@version dist.integrity

matifali reacted with thumbs up emoji

@matifali
Copy link
Member

Just because the person needs to get the sha manually from somewhere.

@matifali
Copy link
Member

matifali commentedApr 2, 2025
edited
Loading

While you are here. There are a few more you might be interested in.

Warn: containerImage not pinned by hash: examples/parameters/build/Dockerfile:1: pin your Docker image by updating ubuntu to ubuntu@sha256:72297848456d5d37d1262630108ab308d3e9ec7ed1c3286a32fe09856619a782Warn: containerImage not pinned by hash: scripts/Dockerfile:9Warn: containerImage not pinned by hash: scripts/Dockerfile.base:4: pin your Docker image by updating alpine:3.21.2 to alpine:3.21.2@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099Warn: containerImage not pinned by hash: scripts/ironbank/Dockerfile:5Warn: goCommand not pinned by hash: dogfood/coder/Dockerfile:25-85Warn: npmCommand not pinned by hash: dogfood/coder/Dockerfile:250Warn: npmCommand not pinned by hash: dogfood/coder/Dockerfile:251Warn: downloadThenRun not pinned by hash: examples/jfrog/docker/build/Dockerfile:25Warn: goCommand not pinned by hash: .github/workflows/ci.yaml:253Warn: goCommand not pinned by hash: .github/workflows/ci.yaml:864Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yaml:214Warn: goCommand not pinned by hash: .github/workflows/security.yaml:100

@sreyasreya merged commitd6c034d intomainApr 2, 2025
30 checks passed
@sreyasreya deleted the jon/pinneddeps branchApril 2, 2025 07:54
@github-actionsgithub-actionsbot locked and limited conversation to collaboratorsApr 2, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account?Sign in.

Reviewers

@matifalimatifalimatifali approved these changes

Assignees

@sreyasreya

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@sreya@matifali

[8]ページ先頭

©2009-2025 Movatter.jp