Skip to content

fix: pin Docker image to exact published version via build arg #patch - #246

Merged
jeff-schnitter merged 1 commit into
mainfrom
fix-docker-version-pin
Oct 2, 2026
Merged

jeff-schnitter merged 1 commit into
mainfrom
fix-docker-version-pin

Conversation

@jeff-schnitter

Copy link
Copy Markdown
Collaborator

Summary

  • Adds ARG VERSION to docker/Dockerfile and changes pip install cortexapps-cli to pip install cortexapps-cli==${VERSION}
  • Passes --build-arg VERSION=${{ env.VERSION }} in publish.yml so Docker always installs the exact version just published to PyPI
  • Eliminates the race condition where Docker could install an older version if PyPI propagation was slow

Test plan

  • CI green
  • Docker Trivy scan passes with correct urllib3 version

🤖 Generated with Claude Code

Prevents Docker from installing a stale PyPI version when the docker
job runs concurrently with pypi publish. VERSION build arg is passed
from the workflow so the image always installs the exact new version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@jeff-schnitter
jeff-schnitter merged commit 32330b2 into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant