Repository navigation
Automate maintenance: package-update releases and Dependabot - #2
Conversation
The app is built on-device, so security fixes in Alpine packages only reach users with a new version. A weekly workflow rebuilds the image, compares its packages with unbound/apk-packages.txt and, after the hardened smoke test and linter, commits a patch release with changelog. Dependabot keeps the Alpine base image and pinned actions current. The app deliberately has no options: options.json is root-only and the container never runs as root. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U8kiCNC4Fjf3vUb6HwLegP
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aba3ea54c3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - uses: actions/checkout@v7.0.1 | ||
|
|
||
| - name: Build image with current Alpine packages | ||
| run: docker build --pull --no-cache -t unbound-pkg:ci unbound |
There was a problem hiding this comment.
Verify aarch64 before publishing the package release
On the ubuntu-latest runner, this plain docker build only builds the native amd64 image. Unlike .github/workflows/ci.yml, which explicitly builds both linux/amd64 and linux/arm64, this workflow then commits the release with GITHUB_TOKEN, and its own comment notes that this push will not trigger CI. Consequently, an Alpine package update that fails to build or run on aarch64 can be published automatically to supported aarch64 users without that architecture ever being checked; build the arm64 target before the commit as well.
Useful? React with 👍 / 👎.
Summary
package-updates.yml: rebuild, compare Alpine packages withunbound/apk-packages.txt, then smoke test, lint and commit a patch release with changelog.github/scripts/package-update.sh: diff, version bump, changelog entry (tested locally for unchanged, changed, added and removed packages)options.json), maintenance overviewTest plan
package-updatesrun onmainreports no changes🤖 Generated with Claude Code
https://claude.ai/code/session_01U8kiCNC4Fjf3vUb6HwLegP