From 7226397eab06f69248d4795f16db6b4c9913aa45 Mon Sep 17 00:00:00 2001 From: Grant McCloskey Date: Fri, 4 Sep 2026 21:32:39 +0000 Subject: [PATCH] build: pin ko base images by digest Every base image in .ko.yaml was referenced by tag only, so two builds of the same commit could produce different images depending on when they ran. debian:stable-slim additionally moves across Debian majors on its own. Pin all three by digest, keeping the tag alongside so a bump can re-resolve it. alpine and debian move to explicit major tags (alpine:3.24, debian:13-slim, the same digests their floating tags resolve to today) so a routine bump never crosses a major; distroless only publishes latest/nonroot, so it stays latest plus digest. Fixes #1498 --- .ko.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.ko.yaml b/.ko.yaml index fd8e859684..0a4a1982c1 100644 --- a/.ko.yaml +++ b/.ko.yaml @@ -12,15 +12,15 @@ # See the License for the specific language governing permissions and # limitations under the License. -defaultBaseImage: gcr.io/distroless/static-debian13 +defaultBaseImage: gcr.io/distroless/static-debian13:latest@sha256:f2ea2709ac8db56323cbd7d014277f32cb572d9ea124b0076f7aafe5980678fe defaultPlatforms: - linux/amd64 - linux/arm64 baseImageOverrides: - github.com/agent-substrate/substrate/demos/sandbox: alpine + github.com/agent-substrate/substrate/demos/sandbox: alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b # ateom-microvm needs glibc (for the fetched cloud-hypervisor binary) and mount/umount - # (to bind the image into the virtiofsd shared dir) — both in debian:stable-slim but + # (to bind the image into the virtiofsd shared dir) — both in debian:13-slim but # not in the distroless static default. - github.com/agent-substrate/substrate/cmd/ateom-microvm: debian:stable-slim + github.com/agent-substrate/substrate/cmd/ateom-microvm: debian:13-slim@sha256:d7e12182ce18b85b93007c1dedf31f2d29e01ccf3182cc4017c709b6259bc132