Propagate same-run parent images to child builds via OCI artifacts - #578
Merged
Merged
Conversation
…tifacts Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
… write advisory) Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
Copilot created this pull request from a session on behalf of
Kanti
October 1, 2026 09:26
View session
Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…image-relationship Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…-only Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…/__w) Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…only OCI gating Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…ntext key correct Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…lly) step Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
…ment Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
Co-authored-by: Kanti <471387+Kanti@users.noreply.github.com>
Use freshly built dependency images for pull requests and manual branch runs. Keep master builds on published images and remove the PR-only gates.
|
1 task done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Child images (e.g.
webdevops/php-nginx:8.4) buildFROM webdevops/php:8.4which, outside ofmaster, resolves to the last published Docker Hub image — not the parent image just built and tested in the same workflow run. PR changes to a parent image therefore never reach its children's tests.CI generator (
ci/src/)GithubCommand::traverse()now passeshasChildren(viaNode::hasChildren()) to the job builder, so it knows without recomputing the graph.GithubJobBuildergained small helpers —hasInternalParent,getCiImageArtifactName,getCiImagePath,parentBuildContext,buildPushWith— replacing inline string concatenation.Parent jobs (nodes with children)
type=oci,tar=false, reusingcache-from: type=ghaso it's effectively cache-only) and upload it withactions/upload-artifact, named per image+tag+arch:Child jobs (nodes with an internal parent)
docker/build-push-actioninvocation with a named build context mapping the exactFROMreference to the downloaded layout:if: github.ref != 'refs/heads/master'.needsnow explicitly includes both the parent build and parent publish jobs ([php_8-4, php_8-4_publish]) instead of just_publish, so children wait on the real build while still running when publish is skipped (non-master) via the existing!failure() && !cancelled()guard.Artifact names/paths are keyed by image+tag+architecture, so amd64/arm64 and different images/tags never collide, and deep chains (
php → php-nginx → php-nginx-dev) each consume their direct parent's artifact only.No registry write permissions, secrets, or
pull_request_targetare involved — propagation is entirely via workflow artifacts, so it works for fork PRs. Master's publish flow is unchanged..github/workflows/build.yamlis regenerated viaci/console github:generate-cito match.