2.0 KiB
DEVX-167: S03 artifact integrity — verify producer artifact + cleanup protection
Problem
S03 (OBL-INFRA-548 REQ-3) requires that dependency PRs only open after the producer artifact exists and is content-addressable, and that registry cleanup never deletes a version pinned by a release manifest. Two gaps:
create_dependency_propens a bump PR unconditionally — if the producer's publish job lagged or failed, the consumer pins a nonexistent artifact.- The sso-bridge image tag is derived from
__init__.py.__version__, which does not always equal the release git tag, so the tag to verify must be decoupled from--new-version.
Approach
REQ-1: create_dependency_pr gains --verify-container <owner/name>
and --container-tag <tag>: before any branch/PR work it resolves the
OCI digest of the image tag via the Gitea packages API (manifest.json
blob sha256) and refuses the PR when the artifact is missing or
unreadable. --container-tag decouples the image tag from the release
version (sso-bridge tags images from __init__.py.__version__, not the
git tag).
REQ-2: Regression tests cover digest resolution, verification-failure
aborts, invalid container format, and the --container-tag override.
Files Affected
src/devx/ci/create_dependency_pr.pysrc/devx/translations.jsontests/unit/test_create_dependency_pr.py
Test Plan
- Unit tests for
resolve_container_digest(digest from manifest blob, missing tag, missing blob, connection error). - CLI tests: verify runs before version lookup, digest resolution, invalid format rejection, container-tag override.
Deploy Plan
Merge via auto-merge after green CI. Producer post-merge workflows adopt the new flags in their own PRs (sso-bridge SSO-22 already passes them).
Rollback Plan
Revert the squash-merge commit; the new options disappear and callers without them behave exactly as before.
Acceptance Criteria
- REQ-1: pre-PR OCI digest verification with --verify-container/--container-tag
- REQ-2: regression tests for all new behavior