Skip to content

phase2(s19): fix container image scan + publish base to GHCR - #108

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-container-image-scan-fix
Apr 29, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
devfrom
phase2-container-image-scan-fix

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Closes Phase 2 slice S19 (container-image-scan-fix).

Two fixes

1. sandbox-images/openclaw/Dockerfile.base — stop failing on the false-negative "openclaw doctor did not stage any node_modules" error. In OpenClaw 2026.4.26 the global `npm install -g openclaw` already resolves all bundled-plugin runtime deps, so `openclaw doctor --fix` legitimately returns early with `missing.length === 0` and creates no staged version dir. Replace the strict count check with a positive sanity check on the four channel deps we ship (grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the `|| true` mask so real doctor failures surface.

2. New .github/workflows/sandbox-base-publish.yml — publish the sandbox base image to GHCR on dev/main pushes. Update `container-scan` in ci.yml to pull from GHCR first (using the auto-provided `GITHUB_TOKEN`), with ACR + local rebuild as fallbacks. PRs no longer rebuild the base from scratch on every run.

Manual follow-up after merge

After the first publish run completes on dev, set the GHCR package `azureclaw-sandbox-base` to private in GitHub Packages settings to preserve the current exposure surface. CI in this repo can still pull a private GHCR image with `GITHUB_TOKEN`.

Files

  • `sandbox-images/openclaw/Dockerfile.base`
  • `.github/workflows/ci.yml` (container-scan job)
  • `.github/workflows/sandbox-base-publish.yml` (new)
  • `CHANGELOG.md`
  • `docs/security-audits/2026-04-29-phase2-container-image-scan-fix-s19.md`

Verification

This is the first PR where the Container Image Scan job is expected to actually go green — that's the verification.

Dockerfile.base no longer fails on "openclaw doctor did not stage any
node_modules" — that condition is now expected (openclaw 2026.4.26 resolves
bundled-plugin runtime deps via the global npm install, so doctor returns
early with missing.length === 0). Replace the strict ≥1 staged-version-dir
check with a positive sanity check on the four channel deps we ship
(grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the
`|| true` mask so real doctor failures surface.

Also publish the sandbox base image to GHCR on dev/main pushes via a new
sandbox-base-publish.yml workflow, and have container-scan in ci.yml log
into GHCR with GITHUB_TOKEN to pull the cached image first (ACR fallback,
local rebuild as last resort). Set the GHCR package to private after the
first publish to preserve current exposure surface.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 4b090af into dev Apr 29, 2026
15 of 16 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-container-image-scan-fix branch April 29, 2026 21:38
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
Dockerfile.base no longer fails on "openclaw doctor did not stage any
node_modules" — that condition is now expected (openclaw 2026.4.26 resolves
bundled-plugin runtime deps via the global npm install, so doctor returns
early with missing.length === 0). Replace the strict ≥1 staged-version-dir
check with a positive sanity check on the four channel deps we ship
(grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the
`|| true` mask so real doctor failures surface.

Also publish the sandbox base image to GHCR on dev/main pushes via a new
sandbox-base-publish.yml workflow, and have container-scan in ci.yml log
into GHCR with GITHUB_TOKEN to pull the cached image first (ACR fallback,
local rebuild as last resort). Set the GHCR package to private after the
first publish to preserve current exposure surface.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant