Repository navigation
phase2(s19): fix container image scan + publish base to GHCR - #108
Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit intoApr 29, 2026
Merged
Conversation
Dockerfile.base no longer fails on "openclaw doctor did not stage any node_modules" — that condition is now expected (openclaw 2026.4.26 resolves bundled-plugin runtime deps via the global npm install, so doctor returns early with missing.length === 0). Replace the strict ≥1 staged-version-dir check with a positive sanity check on the four channel deps we ship (grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the `|| true` mask so real doctor failures surface. Also publish the sandbox base image to GHCR on dev/main pushes via a new sandbox-base-publish.yml workflow, and have container-scan in ci.yml log into GHCR with GITHUB_TOKEN to pull the cached image first (ACR fallback, local rebuild as last resort). Set the GHCR package to private after the first publish to preserve current exposure surface. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2-container-image-scan-fix
branch
April 29, 2026 21:38
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Dockerfile.base no longer fails on "openclaw doctor did not stage any node_modules" — that condition is now expected (openclaw 2026.4.26 resolves bundled-plugin runtime deps via the global npm install, so doctor returns early with missing.length === 0). Replace the strict ≥1 staged-version-dir check with a positive sanity check on the four channel deps we ship (grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the `|| true` mask so real doctor failures surface. Also publish the sandbox base image to GHCR on dev/main pushes via a new sandbox-base-publish.yml workflow, and have container-scan in ci.yml log into GHCR with GITHUB_TOKEN to pull the cached image first (ACR fallback, local rebuild as last resort). Set the GHCR package to private after the first publish to preserve current exposure surface. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes Phase 2 slice S19 (container-image-scan-fix).
Two fixes
1.
sandbox-images/openclaw/Dockerfile.base— stop failing on the false-negative "openclaw doctor did not stage any node_modules" error. In OpenClaw 2026.4.26 the global `npm install -g openclaw` already resolves all bundled-plugin runtime deps, so `openclaw doctor --fix` legitimately returns early with `missing.length === 0` and creates no staged version dir. Replace the strict count check with a positive sanity check on the four channel deps we ship (grammy, @discordjs/opus, @slack/bolt, @larksuiteoapi/node-sdk). Drop the `|| true` mask so real doctor failures surface.2. New
.github/workflows/sandbox-base-publish.yml— publish the sandbox base image to GHCR on dev/main pushes. Update `container-scan` in ci.yml to pull from GHCR first (using the auto-provided `GITHUB_TOKEN`), with ACR + local rebuild as fallbacks. PRs no longer rebuild the base from scratch on every run.Manual follow-up after merge
After the first publish run completes on dev, set the GHCR package `azureclaw-sandbox-base` to private in GitHub Packages settings to preserve the current exposure surface. CI in this repo can still pull a private GHCR image with `GITHUB_TOKEN`.
Files
Verification
This is the first PR where the Container Image Scan job is expected to actually go green — that's the verification.