From 03af8ee875a944028cbca7058382914c7e2e84aa Mon Sep 17 00:00:00 2001 From: Jeff Schnitter Date: Fri, 2 Oct 2026 11:20:57 -0700 Subject: [PATCH] fix: pin Docker image to exact published version via build arg #patch Prevents Docker from installing a stale PyPI version when the docker job runs concurrently with pypi publish. VERSION build arg is passed from the workflow so the image always installs the exact new version. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/publish.yml | 2 +- docker/Dockerfile | 6 ++++-- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 48acb5d3..0d892eab 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -157,7 +157,7 @@ jobs: id: build-docker-image working-directory: ./docker run: | - docker build -t ${{ env.DOCKER_IMAGE }} . + docker build --build-arg VERSION=${{ env.VERSION }} -t ${{ env.DOCKER_IMAGE }} . sha=$(docker images --format {{.ID}} --no-trunc ${{ env.DOCKER_ORGANIZATION }}/cli:${{ env.VERSION }}) echo "SHA=${sha}" >> $GITHUB_OUTPUT echo "URL=https://hub.docker.com/layers/${{ env.DOCKER_ORGANIZATION }}/cli/${{ env.VERSION }}/images/${sha}" >> $GITHUB_OUTPUT diff --git a/docker/Dockerfile b/docker/Dockerfile index 9fd42b90..ece966a2 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -1,11 +1,13 @@ FROM python:3.13-slim +ARG VERSION + RUN pip install --upgrade pip "setuptools>=78.1.1" "msgpack>=1.2.1" RUN apt update && apt upgrade -y && apt install -y jq yq RUN useradd -m cortex -ADD config /home/cortex/.cortex/config +ADD config /home/cortex/.cortex/config -RUN python -m pip install cortexapps-cli +RUN python -m pip install cortexapps-cli==${VERSION} WORKDIR /home/cortex USER cortex