Skip to content

Commit 9c3b85c

Browse files
jamesadevinegithub-actions[bot]Copilot
authored
fix: pin AWF container images to specific firewall version (#32)
Pull versioned Docker images using bare semver tags (OCI convention) instead of :latest to ensure reproducible builds, then tag them as :latest for backward compatibility with AWF. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 964aa81 commit 9c3b85c

1 file changed

Lines changed: 8 additions & 8 deletions

File tree

templates/base.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -193,10 +193,10 @@ jobs:
193193
displayName: "Download AWF (Agentic Workflow Firewall) v{{ firewall_version }}"
194194
195195
- bash: |
196-
docker pull ghcr.io/github/gh-aw-firewall/squid:v{{ firewall_version }}
197-
docker pull ghcr.io/github/gh-aw-firewall/agent:v{{ firewall_version }}
198-
docker tag ghcr.io/github/gh-aw-firewall/squid:v{{ firewall_version }} ghcr.io/github/gh-aw-firewall/squid:latest
199-
docker tag ghcr.io/github/gh-aw-firewall/agent:v{{ firewall_version }} ghcr.io/github/gh-aw-firewall/agent:latest
196+
docker pull ghcr.io/github/gh-aw-firewall/squid:{{ firewall_version }}
197+
docker pull ghcr.io/github/gh-aw-firewall/agent:{{ firewall_version }}
198+
docker tag ghcr.io/github/gh-aw-firewall/squid:{{ firewall_version }} ghcr.io/github/gh-aw-firewall/squid:latest
199+
docker tag ghcr.io/github/gh-aw-firewall/agent:{{ firewall_version }} ghcr.io/github/gh-aw-firewall/agent:latest
200200
displayName: "Pre-pull AWF container images (v{{ firewall_version }})"
201201
202202
{{ prepare_steps }}
@@ -354,10 +354,10 @@ jobs:
354354
displayName: "Download AWF (Agentic Workflow Firewall) v{{ firewall_version }}"
355355
356356
- bash: |
357-
docker pull ghcr.io/github/gh-aw-firewall/squid:v{{ firewall_version }}
358-
docker pull ghcr.io/github/gh-aw-firewall/agent:v{{ firewall_version }}
359-
docker tag ghcr.io/github/gh-aw-firewall/squid:v{{ firewall_version }} ghcr.io/github/gh-aw-firewall/squid:latest
360-
docker tag ghcr.io/github/gh-aw-firewall/agent:v{{ firewall_version }} ghcr.io/github/gh-aw-firewall/agent:latest
357+
docker pull ghcr.io/github/gh-aw-firewall/squid:{{ firewall_version }}
358+
docker pull ghcr.io/github/gh-aw-firewall/agent:{{ firewall_version }}
359+
docker tag ghcr.io/github/gh-aw-firewall/squid:{{ firewall_version }} ghcr.io/github/gh-aw-firewall/squid:latest
360+
docker tag ghcr.io/github/gh-aw-firewall/agent:{{ firewall_version }} ghcr.io/github/gh-aw-firewall/agent:latest
361361
displayName: "Pre-pull AWF container images (v{{ firewall_version }})"
362362
363363
- bash: |

0 commit comments

Comments
 (0)