ci: schedule weekly IL4 development image rebuilds - #3074
terryozaki-wq wants to merge 4 commits into
Conversation
Install the IL4 workflow on the default branch so GitHub can schedule Monday 09:23 UTC runs. Scheduled builds explicitly check out IL4-dev, refresh the current Iron Bank version tags, validate offline, and publish to GHCR. No IL4 application code is merged into dev. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep reporting disabled by default and run it after image publication. Pin the scanner checksum, retain reports for 14 days, and surface generation or upload errors without gating development publishing. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Safeguards publication verified: IL4-dev commit 4b16a6b built successfully in 6m48s: https://github.com/SEMOSS/Semoss/actions/runs/36818950363 . Source tests and offline image checks passed, then GHCR publication completed. Published digest: |
Findings
|
Summary
Development configuration
Uses the existing CodeBuild project and owner-confirmed REPO_ONE_* repository secrets, without an environment approval gate, as requested for pure development. The existing SEMOSS Ubuntu tooling container is digest-pinned to avoid the CodeBuild host glibc incompatibility with Node 24. Application bases remain Iron Bank images.
Validation
ghcr.io/semoss/semoss-il4@sha256:060aa47f04e5f6c69c8fc6e6d020f0beae5e9ab0469df6f1ebc5eb3091ec73ae.Activation and limitations
GitHub schedules only run from the default branch, so the weekly schedule becomes active after this PR is merged. Scheduled runs build IL4-dev, not dev. This does not deploy the image or establish IL4 authorization. The container sources and detailed guide are already on IL4-dev under docker/il4.
Opt-in safeguards update