Auto-update melange image if older than 30 days - #30
Merged
Merged
Conversation
Member
Author
|
Hmmm it won't show the prompt by default it seems, oh well. |
stevebeattie
approved these changes
Apr 7, 2026
stevebeattie
left a comment
Member
There was a problem hiding this comment.
Beyond one minor nit that doesn't necessarily need to block landing this looks good to me.
dannf
approved these changes
Apr 9, 2026
Automatically checks the age of the local melange Docker image and pulls an updated version if it's older than 30 days. Gives users a 15-second window to abort with Ctrl+C before pulling.
…gurable Addresses the review feedback on #30: - The age check now runs after argument parsing, so `--help` no longer touches docker (stevebeattie). - The default threshold drops from 30 to 7 days and is configurable with `--max-image-age-days DAYS`; 0 refreshes on every run (dannf). - `docker_image_outdated()` returns a bool and the first `docker run` of the invocation carries `--pull=always` when it is true, replacing the two separate `docker pull` paths (dannf). A missing image takes the same route as a stale one. Also fixes timestamp parsing. `docker image inspect` prints RFC 3339 with up to nanosecond precision (the shellcheck image reports 2025-07-31T02:42:03.371039353Z) and datetime.fromisoformat() on Python 3.9 and 3.10 rejects anything but 0, 3 or 6 fractional digits, while setup.cfg still declares python_requires >= 3.9. The fraction is now stripped before parsing; verified under python:3.10-alpine. The shellcheck image is pinned by digest, so it is left alone: a digest never goes stale and `docker run` already pulls a missing one.
AmberArcadia
force-pushed
the
auto-update-melange-image-clean
branch
from
October 2, 2026 17:50
c10d026 to
2cde8d7
Compare
Member
Author
|
Pushed 2cde8d7 on top of a rebase onto main. It addresses all three review asks: the image check now runs after argument parsing (so |
xnox
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
shellcheck-run-stepscompiles each package withcgr.dev/chainguard/melange:latest.docker runnever refreshes a local copy of that tag, so new config fields (for exampletest-resources) fail to compile until someone pulls by hand. This PR refreshes the image when the local copy is missing or older than a threshold.How
docker_image_outdated(image, max_age)readsdocker image inspect --format {{.Created}}and returnsTruewhen the image is absent or older thanmax_age.docker run ... compileof the invocation carries--pull=always; later files in the same invocation go back to--pull=missing. One pull code path, and a missing image takes the same route as a stale one.args: [--max-image-age-days=N];0refreshes on every run.--helpnever touches docker.Review feedback
--helpcould trigger a pull. Moved.docker pullpaths with a boolean check plus--pull always. Done.DefaultShellCheckImageis pinned by digest, so it never goes stale, anddocker runalready pulls a missing one.Bug fixed along the way
docker image inspectprints RFC 3339 with up to nanosecond precision; the shellcheck image on my machine reports2025-07-31T02:42:03.371039353Z.datetime.fromisoformat()on Python 3.9 and 3.10 accepts only 0, 3 or 6 fractional digits and raisesInvalid isoformat string, whilesetup.cfgkeepspython_requires = >=3.9. The melange image happened to report2026-09-23T13:50:55Zwith no fraction, which is why the earlier version worked. The fraction is now stripped before parsing.Verification
pre-commit run --all-filespasses (ruff, mypy, reorder-python-imports, shellcheck).--helpprints the new option and exits without a docker call.--max-image-age-days 0 -- -S error -- os/zfs.yamlin a stereo checkout printedcgr.dev/chainguard/melange:latest is 9 days old; refreshing it, docker reportedStatus: Downloaded newer image, and the compile and shellcheck ran as before. The default run right after did not pull.parse_docker_timestampunderpython:3.10-alpine:Note
pre-commit runs hooks in parallel batches unless
require_serial: true, so with many files several processes may each decide to refresh. Docker serialises the layer download, so the cost is a few extra registry checks; not worth making the hook serial.