• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

MapColonies / shigola / 1c027ee63
57%
master: 44%

Build:
Build:
LAST BUILD BRANCH: chore/drop-vendor
DEFAULT BRANCH: master
Ran 15 Sep 2026 10:11AM UTC
Jobs 1
Files 126
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Sep 2026 10:08AM UTC coverage: 55.662%. Remained the same
1c027ee63

push

github

web-flow
ci(release): publish the release image from the org's workflow (MAPCO-11503) (#29)

* ci(release): assert the images a release published

The release push already built both architectures and tagged the version
and latest. What it never did was look at the result: the assertion in
this job runs against the image the runner loaded, which buildx can only
produce for one platform, and which is not what the registry ends up
serving. A release could publish an arm64 image reporting "version not
set" and go green.

So the assertion is now a pair, and the two halves say different things.
The existing one keeps its job -- it proves the build args reached the
compiler, it runs on pull requests, and it fails before anything is
pushed. The new one pulls both architectures of both tags back out of the
registry afterwards and holds each to the released version. Holding
latest to that version is deliberate: a latest still pointing at the
previous release is a real outcome and nothing else would notice it.
--pull always is load-bearing, because the runner is still holding the
layers it just built and a tag pointing at them.

The other half is failing early rather than obscurely. A release with no
ACR_URL does already fail, but not where it looks: the reference falls
back to `local/vector/shigola`, whose first component carries no dot or
colon, so docker reads it as a Docker Hub path rather than a registry
host. The release builds for minutes and then tries to publish to a
registry we do not own, failing there on authorization and naming no
secret. The preflight fails first and says which secret is missing. It is
gated on a release for the reason the publish step is: skipping an edge
push without credentials costs nothing, and a release that publishes
nothing and reports success is the failure this repository has already
had twice.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* test(build): guard what a release publishes

Every way an image pu... (continued)

5810 of 10438 relevant lines covered (55.66%)

122.86 hits per line

Jobs
ID Job ID Ran Files Coverage
1 1c027ee63.1 15 Sep 2026 10:11AM UTC 126
55.66
GitHub Action Run
Source Files on build 1c027ee63
  • Tree
  • List 126
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 1c027ee6 on github
  • Prev Build on development (#8783EC544)
  • Next Build on development (#640E1DF09)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc