Support digest pinning #892
Open
opened 2026-07-26 20:42:26 +00:00 by sixsmith
·
2 comments
No Branch/Tag Specified
main
renovate/golang-1.26
renovate/github.com-charmbracelet-lipgloss-2.x
renovate/github.com-charmbracelet-bubbletea-2.x
renovate/tonistiigi-xx-1.x
renovate/alpine-3.x
renovate/github.com-charmbracelet-log-2.x
chore-deps
fix/492
fix/deps
fix/613
0.13.0-beta
0.13.0-rc2-beta
0.13.0-rc1-beta
0.12.0-beta
0.11.0-beta
0.10.1-beta
0.10.0-beta
0.10.0-rc2-beta
0.10.0-rc1-beta
0.9.0-beta
0.8.1-beta
0.8.0-beta
0.8.0-rc2-beta
0.8.0-rc1-beta
0.7.0-beta
0.7.0-rc3-beta
0.7.0-rc2-beta
0.6.0-beta
0.5.1-beta
0.5.0-alpha
0.4.1-alpha
0.4.0-alpha
0.4.0-alpha-rc8
0.4.0-alpha-rc7
0.4.0-alpha-rc6
0.4.0-alpha-rc5
0.4.0-alpha-rc4
0.4.0-alpha-rc3
0.4.0-alpha-rc2
0.4.0-alpha-rc1
0.3.1-alpha-rc2
0.3.1-alpha-rc1
0.3.1-rc1
0.3.0-alpha
0.2.2-alpha
0.2.1-alpha
0.2.0-alpha
0.1.8-alpha
0.1.7-alpha
0.1.6-alpha
0.1.5-alpha
0.1.4-alpha
0.1.3-alpha
0.1.2-alpha
0.1.1-alpha
0.1.0-alpha
10.0.5
10.0.3
10.0.2
10.0.1
10.0.0
9.0.0
8.0.1
8.0.0
0.7.4
0.7.3
0.7.2
0.7.1
0.7.0
checkout
0.6.0
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
0.1.2
0.1.1
0.1.0
Labels
Clear labels
bug
build
ci/cd
critical fix
design
documentation
duplicate
easy-first-issue
enhancement
help wanted
i10n
i18n
installer
invalid
question
release
release-candidate
security
tech-debt
test
wontfix
Something is not working
go build related issues
Building things with CI/CD
https://docs.coopcloud.tech/federation/resolutions/passed/010/
UI/UX
Documenting all the things
This issue or pull request already exists
Something for new people to get stuck into. We hope it's easy!
New feature
Need some help
Everything to do with localisation
Everything to do with internationalisation
Everything to do with the install script.
Something is wrong
More information is needed
Release management
Related to the new release candidate
Security related
Unit/integration testing
This won't be fixed
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
3wordchant
aadil (Aadil Ayub)
abra-bot (Abra Bot)
ammaratef45
amras (Sarma)
Apfelwurm
BornDeleuze
Brooke
carla
cas (Cassowary)
coopcloud
cyrnel
decentral1se (d1)
dede
devydave
fauno (fauno)
iexos
jade (Jade Ambrose)
jjsfunhouse
jmakdah2 (Jackie Makdah)
joe-irving (Joe Irving)
kawaiipunk (KawaiiPunk)
knoflook
kolaente
lambdabundesverband
linnealovespie (April)
moosemower
moritz
notplants
oxaliq (sorrel)
p4u1
pharaohgraphy (Andrew 🐦🔥❤️🔥✴️)
renovate-bot (Comrade Renovate Bot)
ripclap
simon
sixsmith (Sixsmith)
stevensting
trav
val (val (he/him))
yksflip
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: toolshed/abra#892
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Recipes reference images by tag (e.g. nginx:1.25), which can be mutable (the same tag can point to a different image over time).
This can break reproducibility: If an upstream image is changed between two deploys, the same recipe/version would then pull different images. It's also a supply-chain risk: an upstream image maintainer can push a backdoored image to an other wise trusted tag, which gets pulled silently on next deploy/upgrade.
Proposed Solution
abra app upgradeshould suport be an upgrade path - pinning upgrading an image to a specific digestabrashould resolve and record digests for image tagscompose.ymlby image digestComments
At a high level, I'd like to leave tags intact as the "interface" for
abraCLI users and for digests to be an under-the-hood detail. Opening this issue for discussion before implementation.I was there, Gandalf. I was there, 5 years ago.
I fully agree! We never got there.
I am not sure about the "under-the-hood" aspect. The recipe config is a site of hacking for most recipe maintainers, where people want to have a high level of control. I think we'd probably want to make
abrahave more convenience commands for upgrading / inspecting digests per-image or with a specific upgrade/rollback interface.This would need to be introduced gradually and be backwards compatible. Tricky business. It might even require some decision making.
Hah! Didn't know that history. The justifications offered there still apply today, imo.
I should clarify that
abra recipe upgradeshould keep showing tags as options in the picker, instead of more mysterious digests. It should write the corresponding digest to the composefile, though.Agree to the gradual bit (I'm thinking a boolean flag
--pindigeststhat defaults false, plus making sure other subcommands can handle either tags or digests). So pinning would be initiated by a manual upgrade process. This should let each recipe make its own decision about when to pin.Side note, we'd have to consider that renovatebot might open PRs that clobber digests back into tags.