Implement devcontainer-lock.json
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- go
- 领域
- build-system, devops
调研方向
从链接的 devcontainer lockfile 规范开始,并与 VS Code example repository 进行比较。追踪此项目如何读取 devcontainer.json 并构建镜像,然后将完成定义为:在 devcontainer-lock.json 中记录每个 feature 的确切版本、下载信息和 checksum,同时涵盖可复现性、缓存和 checksum 检测。
由索引模型根据 Issue 内容生成。
描述
See the original spec : https://github.com/devcontainers/spec/blob/main/docs/specs/devcontainer-lockfile.md
Example repo : https://github.com/microsoft/vscode/blob/main/.devcontainer/devcontainer-lock.json
Goal
Introduce a lockfile that records the exact version, download information and checksums for each feature listed in the devcontainer.json.
This will allow for:
- Improved reproducibility of image builds (installing "latest" of a tool will still have different outcomes as the tool publishes new releases).
- Improved cachability of image builds (image cache checksums will remain stable when the lockfile pins a feature to a particular version).
- Improved security by detecting when a feature's release artifact changes after its checksum was first recorded in the lockfile ("trust on first use").
Useful resources:
- 主要语言
- Go
- 星标
- 300
- 派生
- 64
- 平均合并
- 20 分钟
- 30 天内合并 PR
- 1
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
coder/envbuilder 的其他 Issue
-
bug
难度 1/5 1 小时以内 新手友好度 90/100
coder/envbuilder#506 ·
-
bug envbuilder needs-investigation
难度 4/5 3-5 天 新手友好度 35/100
coder/envbuilder#495 ·
-
envbuilder Feature
难度 3/5 1-2 天 新手友好度 56/100
coder/envbuilder#492 ·
-
难度 4/5 3-5 天 新手友好度 25/100
coder/envbuilder#484 ·
-
难度 3/5 1-2 天 新手友好度 38/100
coder/envbuilder#483 ·
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
-
enhancement
难度 2/5 1-3 小时 新手友好度 65/100
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
santhosh-tekuri/jsonschema#276 ·