Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Delete Package Versions workflow deletes the platform manifests of every multi-arch image, so no image tag can be pulled

Aperta
#1,760 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
72/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
docker, docker-compose, github-actions, yaml
Ambito
devops, release

Direzione di ricerca

Read .github/workflows/delete-package-versions.yaml alongside the build job in .github/workflows/release.yaml to understand how cleanup interacts with multi-platform images. There are no unit or Playwright tests; verify the change on a throwaway package by pushing a two-platform image, running cleanup, and confirming docker manifest inspect and an ARM64 docker pull still succeed.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Area: Infrastructure Bug Difficulty: Low Priority: High

Running the "Delete Package Versions" workflow would break every published container image. Each step calls actions/delete-package-versions with delete-only-untagged-versions: true and min-versions-to-keep: 0, which removes every untagged version of the package. release.yaml builds each image for linux/amd64,linux/arm64 with buildx. A tag such as latest or 2.5.2 therefore names an OCI image index, and that index references its per-platform manifests and buildx attestation manifests by digest only. GHCR lists each of those child manifests as its own untagged package version, so the workflow deletes them. Every tag then points at an index whose manifests are gone. docker compose pull and docker compose up -d fail with manifest unknown for api, gateway, playground and web, for latest and for every past release. Existing deployments cannot upgrade, new ones cannot install, and recovery means re-running a release build for every version still in use.

Where

.github/workflows/delete-package-versions.yaml:11-18 (repeated for gateway, playground and web):

- name: Delete API
  uses: actions/delete-package-versions@v5
  with:
    owner: DouglasNeuroInformatics
    package-name: open-data-capture-api
    package-type: container
    min-versions-to-keep: 0
    delete-only-untagged-versions: true

.github/workflows/release.yaml (build job): platforms: linux/amd64,linux/arm64.

The published latest index today references four untagged manifests:

$ docker manifest inspect ghcr.io/douglasneuroinformatics/open-data-capture-api:latest
application/vnd.oci.image.index.v1+json
sha256:6e24ef238f75… linux/amd64
sha256:b8de304fc599… linux/arm64
sha256:120cd90f5e46… unknown/unknown   (attestation)
sha256:242d12b68111… unknown/unknown   (attestation)

Reproduce

  1. Dispatch the "Delete Package Versions" workflow from the Actions tab. Its one run so far, on 2026-08-06, was cancelled before any step ran.
  2. Run docker pull ghcr.io/douglasneuroinformatics/open-data-capture-api:latest.

Actual: the per-platform and attestation manifests are deleted along with stale untagged builds, and the pull fails with manifest unknown.
Expected: only versions that no tag can reach are deleted, so every tagged image still pulls on both platforms.

Tests

No unit or Playwright test can exercise GHCR. Verify the fix on a throwaway package first. Push a two-platform image, run the cleanup, then confirm that docker manifest inspect <image>:<tag> resolves and that docker pull --platform linux/arm64 <image>:<tag> succeeds.

Suggested fix

Replace the action with one that understands multi-platform images, such as dataaxiom/ghcr-cleanup-action pinned to a commit SHA. It deletes untagged versions but keeps the manifests a tagged index references. If nothing needs that cleanup, delete the workflow instead.

Lingua principale
TypeScript
Stelle
119
Fork
19
Merge medio
1g 2h
PR unite (30g)
56

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di DouglasNeuroInformatics/OpenDataCapture

Tutte le issue di DouglasNeuroInformatics/OpenDataCapture

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.