Conversation
Co-authored-by: opencode <opencode@noreply.opencode.ai> Co-authored-by: GitHub Copilot <copilot@noreply.github.com> intent(image-freshness): scheduled package and virus-signature refreshes must execute again even when Dockerfile inputs are unchanged. decision(base-images): always pull referenced bases so floating hardened tags receive updates; preserve digest pins. rejected(cache-default): disabling cache globally would repeat expensive application builds; callers opt out instead. rejected(compression): retain BuildKit defaults until compatibility testing demonstrates a need for forced gzip.
4 of 6 tasks
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The looped no-cache test reuses accumulated outputs, allowing three intended scenarios to pass without being verified.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds optional fresh Docker image rebuilds while preserving normal caching behavior.
Changes:
- Adds
docker-build-no-cacheinput and cache controls. - Always checks base images for updates.
- Documents and tests fresh-build behavior.
| File | Description |
|---|---|
action.yml |
Wires fresh-build settings into Buildx. |
scripts/resolve-build-config.sh |
Resolves external cache configuration. |
tests/resolve-build-config.bats |
Tests cache behavior and validation. |
README.md |
Documents the new input and behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: opencode <opencode@noreply.opencode.ai> Co-authored-by: GitHub Copilot <copilot@noreply.github.com> learned(cache-tests): assertions read the first output entry, so accumulated outputs masked failures in later mode and architecture combinations.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

CORE-5013
Type of Change
Description
Goal: let scheduled image rebuilds refresh packages and virus signatures without disabling caching for ordinary application builds.
Builds always check referenced base images for updates. The optional
docker-build-no-cacheinput reruns Dockerfile steps and skips external cache transfers; it defaults to false. Digest-pinned bases remain pinned.Dependencies: first of three PRs: this action → gha-workflows #520 → custom-images #537. The template exposes this input; the migration enables it to prevent cached ClamAV signatures.
Merge and release this first, then update the template’s temporary commit pin to the released SHA.
Review: check default cache behavior, opt-out handling, and the global
pull: truechange. ShellCheck and all 144 Bats tests passed; live build verification remains pending.Checklist