Skip to content

Automate maintenance: package-update releases and Dependabot - #2

Merged
TimInTech merged 1 commit into
mainfrom
feat/maintenance-automation
Sep 13, 2026
Merged

TimInTech merged 1 commit into
mainfrom
feat/maintenance-automation

Conversation

@TimInTech

Copy link
Copy Markdown
Owner

Summary

  • Weekly package-updates.yml: rebuild, compare Alpine packages with unbound/apk-packages.txt, then smoke test, lint and commit a patch release with changelog
  • .github/scripts/package-update.sh: diff, version bump, changelog entry (tested locally for unchanged, changed, added and removed packages)
  • Dependabot for the Alpine base image and pinned GitHub Actions
  • Docs: why the app has no options (root-only options.json), maintenance overview

Test plan

  • Script: unchanged list → no change; tampered list → 1.1.1 with correct changelog; rerun → no change
  • ShellCheck v0.11.0, actionlint 1.7.12, dependabot.yml parses
  • CI green on this PR
  • After merge: manual package-updates run on main reports no changes
  • End-to-end release path on a throwaway branch with a tampered list

🤖 Generated with Claude Code

https://claude.ai/code/session_01U8kiCNC4Fjf3vUb6HwLegP

The app is built on-device, so security fixes in Alpine packages only
reach users with a new version. A weekly workflow rebuilds the image,
compares its packages with unbound/apk-packages.txt and, after the
hardened smoke test and linter, commits a patch release with changelog.
Dependabot keeps the Alpine base image and pinned actions current.
The app deliberately has no options: options.json is root-only and the
container never runs as root.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U8kiCNC4Fjf3vUb6HwLegP
@TimInTech
TimInTech merged commit 2d62ba5 into main Sep 13, 2026
4 checks passed
@TimInTech
TimInTech deleted the feat/maintenance-automation branch September 13, 2026 10:55

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aba3ea54c3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

- uses: actions/checkout@v7.0.1

- name: Build image with current Alpine packages
run: docker build --pull --no-cache -t unbound-pkg:ci unbound

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Verify aarch64 before publishing the package release

On the ubuntu-latest runner, this plain docker build only builds the native amd64 image. Unlike .github/workflows/ci.yml, which explicitly builds both linux/amd64 and linux/arm64, this workflow then commits the release with GITHUB_TOKEN, and its own comment notes that this push will not trigger CI. Consequently, an Alpine package update that fails to build or run on aarch64 can be published automatically to supported aarch64 users without that architecture ever being checked; build the arm64 target before the commit as well.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant