Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Base image pinned by its multi-arch index digest, so a re-pushed tag cannot
# change what is built. Refresh the digest and the tag together.
FROM python:3.11.16-slim-bookworm@sha256:a36c24f9cbdf4fd0f52d67f0823eeac19c2028c637cecc392d97f980d4fec56b AS builder
FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS builder

ENV PIP_DISABLE_PIP_VERSION_CHECK=1 \
PIP_NO_CACHE_DIR=1
Expand All @@ -14,7 +14,7 @@ COPY pyproject.toml README.md LICENSE NOTICE ./
COPY src ./src
RUN python -m pip wheel --no-deps --no-build-isolation --wheel-dir /wheels .

FROM python:3.11.16-slim-bookworm@sha256:a36c24f9cbdf4fd0f52d67f0823eeac19c2028c637cecc392d97f980d4fec56b AS runtime
FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS runtime

ENV PIP_DISABLE_PIP_VERSION_CHECK=1 \
PIP_NO_CACHE_DIR=1 \
Expand Down
7 changes: 5 additions & 2 deletions tests/unit/test_container_release.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,11 @@

def test_runtime_image_is_multistage_non_root_and_offline_installed() -> None:
dockerfile = Path("Dockerfile").read_text(encoding="utf-8")
# Both stages pin the base image by digest, not by tag alone.
assert dockerfile.count("FROM python:3.11.16-slim-bookworm@sha256:") == 2
# Both stages pin the base image by patch release and digest, not by tag alone.
base_stages = re.findall(
r"^FROM python:3\.11\.\d+-slim-bookworm@sha256:[0-9a-f]{64} AS ", dockerfile, re.M
)
assert len(base_stages) == 2
assert "AS builder" in dockerfile
assert "pip install --require-hashes -r requirements/build.txt" in dockerfile
assert "pip wheel --no-deps --no-build-isolation --wheel-dir /wheels ." in dockerfile
Expand Down
Loading