Delete Package Versions workflow deletes the platform manifests of every multi-arch image, so no image tag can be pulled
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 72/100
Direzione di ricerca
Read .github/workflows/delete-package-versions.yaml alongside the build job in .github/workflows/release.yaml to understand how cleanup interacts with multi-platform images. There are no unit or Playwright tests; verify the change on a throwaway package by pushing a two-platform image, running cleanup, and confirming docker manifest inspect and an ARM64 docker pull still succeed.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Running the "Delete Package Versions" workflow would break every published container image. Each step calls actions/delete-package-versions with delete-only-untagged-versions: true and min-versions-to-keep: 0, which removes every untagged version of the package. release.yaml builds each image for linux/amd64,linux/arm64 with buildx. A tag such as latest or 2.5.2 therefore names an OCI image index, and that index references its per-platform manifests and buildx attestation manifests by digest only. GHCR lists each of those child manifests as its own untagged package version, so the workflow deletes them. Every tag then points at an index whose manifests are gone. docker compose pull and docker compose up -d fail with manifest unknown for api, gateway, playground and web, for latest and for every past release. Existing deployments cannot upgrade, new ones cannot install, and recovery means re-running a release build for every version still in use.
Where
.github/workflows/delete-package-versions.yaml:11-18 (repeated for gateway, playground and web):
- name: Delete API
uses: actions/delete-package-versions@v5
with:
owner: DouglasNeuroInformatics
package-name: open-data-capture-api
package-type: container
min-versions-to-keep: 0
delete-only-untagged-versions: true
.github/workflows/release.yaml (build job): platforms: linux/amd64,linux/arm64.
The published latest index today references four untagged manifests:
$ docker manifest inspect ghcr.io/douglasneuroinformatics/open-data-capture-api:latest
application/vnd.oci.image.index.v1+json
sha256:6e24ef238f75… linux/amd64
sha256:b8de304fc599… linux/arm64
sha256:120cd90f5e46… unknown/unknown (attestation)
sha256:242d12b68111… unknown/unknown (attestation)
Reproduce
- Dispatch the "Delete Package Versions" workflow from the Actions tab. Its one run so far, on 2026-08-06, was cancelled before any step ran.
- Run
docker pull ghcr.io/douglasneuroinformatics/open-data-capture-api:latest.
Actual: the per-platform and attestation manifests are deleted along with stale untagged builds, and the pull fails with manifest unknown.
Expected: only versions that no tag can reach are deleted, so every tagged image still pulls on both platforms.
Tests
No unit or Playwright test can exercise GHCR. Verify the fix on a throwaway package first. Push a two-platform image, run the cleanup, then confirm that docker manifest inspect <image>:<tag> resolves and that docker pull --platform linux/arm64 <image>:<tag> succeeds.
Suggested fix
Replace the action with one that understands multi-platform images, such as dataaxiom/ghcr-cleanup-action pinned to a commit SHA. It deletes untagged versions but keeps the manifests a tagged index references. If nothing needs that cleanup, delete the workflow instead.
- Lingua principale
- TypeScript
- Stelle
- 119
- Fork
- 19
- Merge medio
- 1g 2h
- PR unite (30g)
- 56
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di DouglasNeuroInformatics/OpenDataCapture
-
Area: Playground Bug Difficulty: Low Good First Issue Priority: Low
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
DouglasNeuroInformatics/OpenDataCapture#1805 ·
I maintainer di solito rispondono entro 1 giorno
-
Area: Instruments Bug Difficulty: Low Priority: Low
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
DouglasNeuroInformatics/OpenDataCapture#1801 ·
I maintainer di solito rispondono entro 1 giorno
-
Area: Instruments Bug Difficulty: Low Good First Issue Priority: Low
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
DouglasNeuroInformatics/OpenDataCapture#1800 ·
I maintainer di solito rispondono entro 1 giorno
-
Area: Instruments Bug Difficulty: Low Good First Issue Priority: Low
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
DouglasNeuroInformatics/OpenDataCapture#1799 ·
I maintainer di solito rispondono entro 1 giorno
-
Area: Instruments Bug Difficulty: Low Performance Priority: Medium
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
DouglasNeuroInformatics/OpenDataCapture#1795 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di DouglasNeuroInformatics/OpenDataCapture
Issue simili
-
Add: YRF Music NepalApertastreams:add
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
walletbeat/walletbeat#1558 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
hawk-digital-environments/HAWKI#438 ·
I maintainer di solito rispondono entro 1 giorno
-
Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
GiganticMinecraft/seichi-portal-frontend#1165 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno