Implements sections 1-2-5 of openspec/changes/release-tools-image/tasks.md.
Produces image/release-tools/ containing:
- Containerfile — multi-stage build on Project Hummingbird hi/go base
(registry.access.redhat.com/hi/go:latest-builder; floats until
Hummingbird publishes versioned tags). Bundles: Go toolchain, syft
v1.44.0, goreleaser v2.16.0, cosign v3.0.6, Node 22, npm, jq, curl,
ca-certificates, tar, gzip, xz, @anthropic-ai/mcpb v2.1.2.
- VERSIONS.md — single source of truth for pinned versions + Hummingbird
base digest. Documents the TAG-FLOATING RISK for the base.
- npm/{package.json,package-lock.json} — pinned mcpb dep + integrity
hashes. Containerfile installs via `npm ci --ignore-scripts` plus
`npm install -g` so mcpb is on PATH AND offline npx works.
- .dockerignore — scoped to image/release-tools/ build context.
- renovate.json — Renovate config; Hummingbird base manual, tools auto.
- README.md — operator guide: pull, verify cosign, run locally, bump,
lift-out 5-step procedure.
- build.sh — single-shot local podman build (tag localhost/release-tools:dev).
- verify.sh — runs the built image and asserts every bundled tool's
--version. Covers spec.md scenarios "Image carries a shell" and
"npx can resolve @anthropic-ai/mcpb without network".
End-to-end verifier `bash build.sh && bash verify.sh` exits 0 after 6
fix rounds (tar, gzip, build-context scope, npm offline, symlink-deref
in npm bin). All 10 tool checks green.
Out of scope (iteration 2): .tekton/release-tools/ pipelines for
PR-build + tag-publish.
Refs: forgejo-mcp-1b4
8 lines
248 B
Text
8 lines
248 B
Text
# Build context is image/release-tools/ (passed as SCRIPT_DIR in build.sh).
|
|
# All files in context are already scoped to this directory.
|
|
# Exclude only files not needed inside the image build.
|
|
build.sh
|
|
verify.sh
|
|
README.md
|
|
renovate.json
|
|
VERSIONS.md
|