Publish one manifest and propagate tags by digest#24
Merged
Conversation
Copilot created this pull request from a session on behalf of
Danathar
July 2, 2026 17:37
View session
Replace the hardcoded latest in the push step and the propagation skip with the existing DEFAULT_TAG env knob so the single-push scheme keeps working if the default tag ever changes, and reword the step comment to describe the observed per-push manifest divergence instead of citing a run number. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Danathar
marked this pull request as ready for review
July 2, 2026 18:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Run 143 failed correctly: podman's sequential multi-tag push emitted different manifest bytes for
latestvs the date tags, producing an inconsistent tag set that the verify step caught.Root cause:
redhat-actions/push-to-registrycalled once with all tags pushes each tag as a separate operation, and podman can produce distinct manifests across calls.Fix: Push a single tag (
latest), then copy that manifest to the remaining tags server-side withskopeo copy --preserve-digests. Tag identity becomes structural rather than asserted.Changes:
.github/workflows/build.ymltags: latestinstead of the full tag liststeps.metadata.outputs.tags, skipslatest, copies each via:--preserve-digestsmakes skopeo fail rather than rewrite the manifest, so the existing verify step passes by constructionREADME.md— sync the publish-flow description