diff --git a/.gitea/workflows/lint.yml b/.gitea/workflows/lint.yml index dfedbc0..f597ad5 100644 --- a/.gitea/workflows/lint.yml +++ b/.gitea/workflows/lint.yml @@ -92,7 +92,7 @@ jobs: - name: Install actionlint (pinned) env: - ACTIONLINT_VERSION: 1.7.7 + ACTIONLINT_VERSION: 1.7.12 run: | curl -fsSL \ "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" \ @@ -127,7 +127,7 @@ jobs: - name: Install hadolint (pinned) env: - HADOLINT_VERSION: 2.14.0 + HADOLINT_VERSION: 2.15.1 run: | curl -fsSL \ "https://github.com/hadolint/hadolint/releases/download/v${HADOLINT_VERSION}/hadolint-Linux-x86_64" \ diff --git a/CHANGELOG.md b/CHANGELOG.md index 6372f53..260a39c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -152,6 +152,41 @@ stale — and it needs no secret, since `pi-extensions` is anonymously clonable > alongside the existing `skillset_snapshot_tree_sha256`, which this change does > not add. +**Four pinned dependencies bumped, after an audit of everything the image gets +from outside apt.** The audit itself is the useful part: of ~23 externally-managed +components, the 19 that resolve `latest` at build time were already current or +refresh themselves on the next rebuild, and the hard pins for `pi` (0.85.1), +`mempalace` (3.9.0) and `pi-atelier` (v0.10.1) were all already the newest +available. Only four needed a human. + +**`NODE_VERSION` 22 → 24 (LTS "Krypton") — this one was a latent defect, not +housekeeping.** `agent-browser` publishes `engines.node ">=24.0.0"`, so the image +was *below a declared requirement*: v1.8.14 shipped node 22.23.2 with +`agent-browser` 0.37.1, meaning every build installed it with an npm `EBADENGINE` +warning and then ran the baked browser automation outside its supported range. +The other two npm consumers are satisfied either way — `pi` declares `>=22.19.0`, +`playwright` `>=20`. Verified before bumping, because a missing NodeSource suite +would break every architecture at once: `setup_24.x` returns HTTP 200 and the +`node_24.x` suite advertises `Architectures: amd64 arm64 armhf x86_64`, covering +both the arm64 fleet and the amd64 CI runners. Nothing else in the repo pinned the +node major. + +**`actionlint` 1.7.7 → 1.7.12 and `hadolint` 2.14.0 → 2.15.1**, each run against +the current tree at the new version *before* being pinned — both clean, no new +findings. That ordering is the point: a linter bump is the one dependency update +that can turn CI red on unchanged code, so discovering it locally costs a minute +and discovering it in CI costs a round trip. + +**`SKILLSET_SNAPSHOT_REF` `e9e09d9` → `4d7c0ea`**, via +`scripts/vendor-mempalace-skill.sh` rather than by hand, because that script is +the only thing that may write the ARG — a `cp` without a matching bump produces a +manifest that confidently lies. This turned out to be **provenance-only**: the +recorded ref was 6 commits behind, but `skills/mempalace/SKILL.md` is byte-identical +at both (`3675bfab…`), so the vendored snapshot was already correct and only its +recorded origin was stale. Consequently no `rootfs/` bytes changed, the +smoke-test phrase canary stays valid, and this ARG alone would not have forced a +base rebuild — the node bump does that anyway. + --- ## v1.8.14 — 2026-09-08 diff --git a/Dockerfile.base b/Dockerfile.base index af24267..071939b 100644 --- a/Dockerfile.base +++ b/Dockerfile.base @@ -633,7 +633,17 @@ ENV COLORTERM=truecolor ENV PATH="/home/developer/.local/bin:/home/developer/.cargo/bin:${PATH}" # ── Node.js (required for pi + MCP servers + tldr) ── -ARG NODE_VERSION=22 +# 24 (LTS "Krypton"), raised from 22 on 2026-09-10 because the image was BELOW a +# DECLARED requirement, not merely behind the newest release: `agent-browser` +# publishes engines.node ">=24.0.0", so every build on 22 installed it with an npm +# EBADENGINE warning and then ran it outside its supported range — measured on +# v1.8.14, which shipped node 22.23.2 with agent-browser 0.37.1. The other two npm +# consumers are satisfied either way: pi declares ">=22.19.0" and playwright +# ">=20". Verified before bumping, because a missing NodeSource suite would break +# the build for every arch at once: deb.nodesource.com/setup_24.x returns HTTP 200 +# and the node_24.x suite advertises `Architectures: amd64 arm64 armhf x86_64`, so +# both the arm64 fleet and the amd64 CI runners resolve. +ARG NODE_VERSION=24 RUN curl -fsSL --retry 5 --retry-delay 5 --retry-all-errors https://deb.nodesource.com/setup_${NODE_VERSION}.x | bash - && \ apt-get install -y --no-install-recommends nodejs && \ rm -rf /var/lib/apt/lists/* diff --git a/Dockerfile.variant b/Dockerfile.variant index ed54d8e..eed7999 100644 --- a/Dockerfile.variant +++ b/Dockerfile.variant @@ -392,7 +392,7 @@ ARG MEMPALACE_TOOLKIT_REF=main # no ~67-minute base rebuild. (scripts/check-base-hash.sh scans only # Dockerfile.base, so no folding into the base hash is required — nor would # it be correct, since this ARG changes nothing about the base's contents.) -ARG SKILLSET_SNAPSHOT_REF=e9e09d95f92670536a199fc986dfa24d787f18d1 +ARG SKILLSET_SNAPSHOT_REF=4d7c0ea9caeb3a1d6d9b04cf34f3fca5f9df4985 # Dockerfile.base sets description="pi-devbox — base image (variant-independent)" # and every variant INHERITS it, so both published images used to advertise