forgejo-mcp/image/release-tools/VERSIONS.md
Christoph Görn 508c7c0c68
ci: ✨ add go-licenses check + Conventional Commits PR title gate
- go-licenses v1.6.0 added to release-tools image; license-check step
  in go-ci task fails on forbidden/restricted licenses (GPL/AGPL/LGPL/MPL)
- new commit-title-check task validates PR title AND each PR branch
  commit against Conventional Commits regex using PAC dynamic var
  {{ body.pull_request.title }}; blocks merge before semantic-release
  post-merge analysis would silently drop malformed titles
- on-pull-request pipeline wires commit-title-check as parallel task
  alongside build-and-test; PAC resolves target_branch → base_ref
2026-05-26 15:16:42 +02:00

3.6 KiB

Pinned Tool Versions

This file is the single source of truth for all tool versions baked into the release-tools image. Update this file, then regenerate npm/package-lock.json and rebuild the image.

Base Image

Image Tag Digest Notes
registry.access.redhat.com/hi/go latest-builder sha256:d8c8b702b8a54150e8fdca86753f581d98c551ab8a3fd429886d4ddd4e949894 TAG-FLOATING RISK: Hummingbird has not published a specific MAJOR.MINOR-builder tag as of 2026-05-25; only latest-builder is available. Upgrade to a pinned 1.26-builder or 1.26.3-builder tag when Hummingbird publishes one. Track at https://catalog.redhat.com/software/containers/hi/go/.

Go version shipped: 1.26.3 (from image label org.opencontainers.image.version)

Tools Installed via Build Stage (compiled/fetched)

Tool Version Source SHA256 (linux/amd64 tarball) Notes
syft v1.44.0 prebuilt syft_1.44.0_linux_amd64.tar.gz from anchore releases 0e91737aee2b5baf1d255b959630194a302335d848ff97bb07921eb6205b5f5a Verified against syft_1.44.0_checksums.txt. Binary at /usr/local/bin/syft. Update SYFT_SHA256 ARG in Containerfile on bump.
goreleaser v2.16.0 prebuilt goreleaser_Linux_x86_64.tar.gz from goreleaser releases eaae05b5eba07533bd0f06846b68c808399504784df00c62eb219541fc04e5e2 Verified against checksums.txt. Binary at /usr/local/bin/goreleaser. Update GORELEASER_SHA256 ARG in Containerfile on bump.
cosign v3.0.6 prebuilt cosign-linux-amd64 from sigstore releases see cosign_checksums.txt (runtime-fetched) SHA256 verified at build time against cosign_checksums.txt. Binary at /usr/local/bin/cosign.
govulncheck latest go install golang.org/x/vuln/cmd/govulncheck@latest n/a (go sumdb integrity) Binary at /usr/local/bin/govulncheck; Renovate tracks golang.org/x/vuln
go-licenses v1.6.0 go install github.com/google/go-licenses@v1.6.0 n/a (go sumdb integrity) Binary at /usr/local/bin/go-licenses; used by go-ci task to fail PRs pulling forbidden/restricted licenses (GPL/AGPL/LGPL/MPL). Update GO_LICENSES_VERSION ARG in Containerfile on bump.

Tools Installed via dnf (final stage)

Tool Version Source
node 22.x (from RHEL/UBI stream) dnf install -y nodejs
npm (with nodejs) dnf install -y npm
jq (latest in stream) dnf install -y jq
curl (latest in stream) dnf install -y curl
ca-certificates (latest in stream) dnf install -y ca-certificates

npm Package (@anthropic-ai/mcpb)

Package Version npm Integrity Hash Tarball SHA256
@anthropic-ai/mcpb 2.1.2 see npm/package-lock.json see npm/package-lock.json integrity field
@fission-ai/openspec 1.3.1 see npm/package-lock.json see npm/package-lock.json integrity field

The tarball SHA256 is recorded in npm/package-lock.json under integrity (sha512 format). A manual integrity check: npm pack @anthropic-ai/mcpb@2.1.2 --dry-run and compare hash.

Version Bump Policy

Bump Triggers
MAJOR base image swap, removed bundled tool, removed/moved binary path, breaking CLI change, shell removed from final stage
MINOR new bundled tool, Hummingbird base MINOR bump, Go version bump within same major, bundled tool MINOR bump
PATCH bundled tool PATCH bumps, security backports, rebuild with no observable contract change

Renovate manages automated bump PRs. Go bumps are treated as MINOR (not MAJOR) because goreleaser's CLI contract is unaffected by Go's own backward-compatibility guarantee.