• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

supabase / cli / 36761952394
67%

Build:
DEFAULT BRANCH: develop
Ran 30 Sep 2026 06:56PM UTC
Jobs 1
Files 79
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 06:48PM UTC coverage: 66.737%. Remained the same
36761952394

push

github

web-flow
feat(stack): pin slim artifacts by revision and make the catalog the single version table (#6883)

## Summary

slim-services now publishes immutable `<upstream>-r<N>` releases
(supabase/slim-services#326, #328). This PR makes the CLI consume them
safely and from one place:

- **Pinning.** Every slim artifact is pinned by content: the image
digest, plus an archive and manifest sha256 per target. Nothing is
looked up at runtime.
- **One version table.** The stack catalog
(`packages/stack/src/Artifacts.ts`) is the only place slim-capable
service versions are written down. The new stack, legacy `supabase
start`, and legacy slim mode (`SUPABASE_USE_SLIM_IMAGES`) all derive
from it.
- **Updates.** Upgrades and packaging hotfixes arrive as automated PRs
from slim-services releases.

### Pinning

- **Catalog entries.** They are now `ArtifactPin`s:
  - `upstreamVersion`
  - `revision`
  - `image: …:<U>-r<N>@sha256:…`
- `upstreamImage`: the upstream image slim-services built from or
mirrored, as recorded in the release
  - `natives`: sha256s per target
- **Native downloads.**
- The runtime `SHA256SUMS` and GHCR checksum lookups are gone. The
GitHub release and S3 serve bytes only.
  - The manifest is hash-checked before it is parsed.
  - A mirror that serves the wrong bytes falls through to the next one.
- The cache key is `slim-services/<svc>/<R>/<target>`, so a hotfix
revision gets its own cache entry.

### One version table

- **Generated Dockerfile lines.** The slim-capable `FROM` lines of
`apps/cli/src/shared/services/Dockerfile`, and its Go copy, are
generated from the catalog by
`apps/cli/scripts/render-service-dockerfile.ts`.
- The generator rewrites only those 14 lines, in place, and takes each
repository from the existing line. imgproxy stays on
`darthsim/imgproxy`.
- Kong, `pg14`, and the job images (migra, pg_prove,
pgadmin-schema-diff) are still maintained by hand or by Dependabot.
- A drift test in the required `apps/cli` unit project fails when t... (continued)

4097 of 6139 relevant lines covered (66.74%)

7.37 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36761952394.1 30 Sep 2026 06:56PM UTC 79
66.74
GitHub Action Run
Source Files on build 36761952394
  • Tree
  • List 79
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36761952394
  • 62aac0ff on github
  • Prev Build on gh-readonly-queue/develop/pr-6917-a0711c0c0872c4de7404eb47f0fd30175be7c67d (#36758032458)
  • Next Build on develop (#36830257440)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc