Repository navigation
Conversation
Co-authored-by: opencode <opencode@noreply.opencode.ai> Co-authored-by: GitHub Copilot <copilot@noreply.github.com> intent(image-freshness): scheduled package and virus-signature refreshes must execute again even when Dockerfile inputs are unchanged. decision(base-images): always pull referenced bases so floating hardened tags receive updates; preserve digest pins. rejected(cache-default): disabling cache globally would repeat expensive application builds; callers opt out instead. rejected(compression): retain BuildKit defaults until compatibility testing demonstrates a need for forced gzip.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The looped no-cache test reuses accumulated outputs, allowing three intended scenarios to pass without being verified.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds optional fresh Docker image rebuilds while preserving normal caching behavior.
Changes:
- Adds
docker-build-no-cacheinput and cache controls. - Always checks base images for updates.
- Documents and tests fresh-build behavior.
| File | Description |
|---|---|
action.yml |
Wires fresh-build settings into Buildx. |
scripts/resolve-build-config.sh |
Resolves external cache configuration. |
tests/resolve-build-config.bats |
Tests cache behavior and validation. |
README.md |
Documents the new input and behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: opencode <opencode@noreply.opencode.ai> Co-authored-by: GitHub Copilot <copilot@noreply.github.com> learned(cache-tests): assertions read the first output entry, so accumulated outputs masked failures in later mode and architecture combinations.
| cache-from: type=gha${{ steps.build_config.outputs.cache_suffix }} | ||
| cache-to: type=gha,mode=max${{ steps.build_config.outputs.cache_suffix }} | ||
| # Floating hardened base tags can receive patches without changing name. | ||
| pull: true |
There was a problem hiding this comment.
@Staffbase/workflow-enthusiasts do you think this change is fine as default?
There was a problem hiding this comment.
make sense. We probably don't want GitHub to cache these additionally. Chainguard recommends to tag your images like python:3.13@sha256:asddg.. so this wouldn't be cached anyway. Not sure what will be the impact on GitHub costs

CORE-5013
Type of Change
Description
Goal: let scheduled image rebuilds refresh packages and virus signatures without disabling caching for ordinary application builds.
Builds always check referenced base images for updates. The optional
docker-build-no-cacheinput reruns Dockerfile steps and skips external cache transfers; it defaults to false. Digest-pinned bases remain pinned.Dependencies: first of three PRs: this action → gha-workflows #520 → custom-images #537. The template exposes this input; the migration enables it to prevent cached ClamAV signatures.
Merge and release this first, then update the template’s temporary commit pin to the released SHA.
Review: check default cache behavior, opt-out handling, and the global
pull: truechange. ShellCheck and all 144 Bats tests passed; live build verification remains pending.Checklist