Skip to content

release: v2.2.0+node25.9.0 into maintenance/v2+node25#88

Merged
Amnoor merged 9 commits intomaintenance/v2+node25from
release/v2.2.0+node25.9.0
Apr 4, 2026
Merged

release: v2.2.0+node25.9.0 into maintenance/v2+node25#88
Amnoor merged 9 commits intomaintenance/v2+node25from
release/v2.2.0+node25.9.0

Conversation

@Amnoor
Copy link
Copy Markdown
Member

@Amnoor Amnoor commented Apr 4, 2026

Summary

This PR promotes release/v2.2.0+node25.9.0 into maintenance/v2+node25, marking the next minor release on the Node.js 25 maintenance line. It consolidates five development cycles: the Node.js base image bump from 25.8.2 to 25.9.0, the PR test workflow move from Docker Hub-pushed images to OCI artifact handoff, the docker/build-push-action upgrade to v7 in both workflows, the release workflow attestation update to signed mode=max provenance and SBOM output, and documentation updates aligning examples and CI/CD tooling references with the current release state.

Files Changed

Added:

  • None

Modified:

  • CONTRIBUTING.md
  • Dockerfile
  • README.md
  • .github/
    • workflows/
      • deployment.yml
      • pr-tests.yml

Deleted:

  • None

Key Changes

  • Updated the builder stage base image in Dockerfile from node:25.8.2-alpine3.23 to node:25.9.0-alpine3.23, bumping the bundled Node.js runtime from 25.8.2 to 25.9.0.
  • Updated .github/workflows/pr-tests.yml to stop pushing PR images to Docker Hub by changing the Build Image step from push: true to push: false with outputs: type=oci,dest=image.tar, adding Upload Docker Image Artifact, Download Docker Image Artifact, Extract single-arch image with Skopeo, and artifact-clean-up, and changing the test image flow to local per-architecture images derived from the OCI artifact.
  • Updated .github/workflows/pr-tests.yml from uses: docker/build-push-action@v6 to uses: docker/build-push-action@v7 in the Build Image step, and updated .github/workflows/deployment.yml from uses: docker/build-push-action@v5 to uses: docker/build-push-action@v7 in the Build and push (multi-registry, multi-platform) step.
  • Added id-token: write to the top-level permissions: block in .github/workflows/deployment.yml and replaced provenance: true and sbom: true with attests: entries type=provenance,mode=max and type=sbom,mode=max in the Build and push (multi-registry, multi-platform) step.
  • Updated the Node.js Version Bumps example in CONTRIBUTING.md from node:25.8.2-alpine3.23 to node:25.9.0-alpine3.23, updated the Versioning and Tags example in README.md from v2.1.3+node25.8.2 to v2.2.0+node25.9.0, and added actions/upload-artifact, actions/download-artifact, geekyeggo/delete-artifact, chrnorm/deployment-action, and chrnorm/deployment-status to the CI/CD & Build Tooling section of README.md.

dependabot bot and others added 9 commits April 2, 2026 21:26
Bumps node from 25.8.2-alpine3.23 to 25.9.0-alpine3.23.

---
updated-dependencies:
- dependency-name: node
  dependency-version: 25.9.0-alpine3.23
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…nto the "develop" branch

build(deps): Bump node from 25.8.2-alpine3.23 to 25.9.0-alpine3.23
This merge updates `.github/workflows/pr-tests.yml` to stop pushing PR test images to Docker Hub and instead pass the built image between jobs as an OCI artifact. The test workflow now uploads the multi-arch build output from `build-image`, downloads it in `test-image`, extracts a per-architecture image into the local Docker daemon with `skopeo`, and removes the artifact after testing. The artifact name now includes the pull request number so concurrent PR runs do not share the same artifact identifier.

In `build-image`, the `Login to Docker Hub` step is removed and the `Build Image` step changes from `push: true` to `push: false` with `outputs: type=oci,dest=image.tar`, so the workflow produces a local OCI archive instead of publishing a PR image to Docker Hub. A new `Upload Docker Image Artifact` step uses `actions/upload-artifact@v4` to persist `image.tar` as `docker-image-pr-${{ github.event.pull_request.number }}`. In `test-image`, the Docker Hub login and `docker pull` flow are removed, `TEST_IMAGE` changes from `runtimenode/test:pr-${{ github.event.pull_request.number }}` to `test:pr-${{ github.event.pull_request.number }}`, and new `Download Docker Image Artifact` and `Extract single-arch image with Skopeo` steps load each matrix entry’s `linux/amd64` or `linux/arm64` image as `test:pr-<number>-<arch>`. The smoke test and all integrity checks are updated to resolve `${{ matrix.platform }}` into `ARCH` and run against `${{ env.TEST_IMAGE }}-$ARCH` so they validate the locally extracted per-architecture image. A new `artifact-clean-up` job then removes `docker-image-pr-${{ github.event.pull_request.number }}` using `geekyeggo/delete-artifact@v4` after testing completes.

No other files or workflow jobs are modified by this merge.
…p" branch

This merge updates the GitHub Actions workflows to use `docker/build-push-action@v7` instead of the current older major versions. It applies the version bump in both `.github/workflows/deployment.yml` and `.github/workflows/pr-tests.yml` while keeping the existing build, attestation, cache, and artifact logic unchanged.

In `.github/workflows/deployment.yml`, the `Build and push (multi-registry, multi-platform)` step is updated from `uses: docker/build-push-action@v5` to `uses: docker/build-push-action@v7` without changing the existing `attests:`, tag, label, platform, or cache settings. In `.github/workflows/pr-tests.yml`, the `Build Image` step is updated from `uses: docker/build-push-action@v6` to `uses: docker/build-push-action@v7` without changing the existing OCI archive output, multi-platform build, tag, or cache configuration.

No other files or workflow jobs are modified by this merge.
This merge updates `README.md` and `CONTRIBUTING.md` on `develop` so the documentation reflects the upcoming Node.js `25.9.0` release line and the current CI/CD tooling used by the repository. It refreshes the version examples in both documents and expands the README acknowledgements so recently added workflow actions are documented alongside the existing build and release tooling.

In `CONTRIBUTING.md`, the Node.js Version Bumps example is updated from `node:25.8.2-alpine3.23` to `node:25.9.0-alpine3.23`. In `README.md`, the Versioning and Tags example is updated from `v2.1.3+node25.8.2` to `v2.2.0+node25.9.0`. The CI/CD & Build Tooling section of `README.md` is also expanded to add `actions/upload-artifact`, `actions/download-artifact`, and `geekyeggo/delete-artifact` for the PR test artifact workflow, plus `chrnorm/deployment-action` and `chrnorm/deployment-status` for GitHub Deployment tracking in the release workflow.

No other files or documentation sections are modified by this merge.
@Amnoor Amnoor merged commit 37c8311 into maintenance/v2+node25 Apr 4, 2026
5 checks passed
@Amnoor Amnoor deleted the release/v2.2.0+node25.9.0 branch April 4, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant