From f398b8e87a30bb691aab422cec5b215027133525 Mon Sep 17 00:00:00 2001 From: Miguel Martinez Trivino Date: Mon, 21 Sep 2026 15:45:41 +0200 Subject: [PATCH 1/2] fix(ci): make the sandbox kit workflow parseable A shell comment in the "Add Attestation and Push Kit" step contained the literal empty expression syntax. GitHub expands template expressions across the entire workflow file, including inside run bodies and their comments, so the empty expression failed expression parsing and the whole file was rejected. The workflow never scheduled a job on any release bump, which means no sandbox kit has been published since it was added. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino Chainloop-Trace-Sessions: 1e55d1fc-a673-481e-a278-4cdd9eecb47f --- .github/workflows/package_sandbox_kit.yaml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/package_sandbox_kit.yaml b/.github/workflows/package_sandbox_kit.yaml index d39427f51..26df6dd39 100644 --- a/.github/workflows/package_sandbox_kit.yaml +++ b/.github/workflows/package_sandbox_kit.yaml @@ -142,8 +142,11 @@ jobs: - name: Add Attestation (Sandbox Kit) and Push Kit run: | - # KIT_VERSION arrives through env, not ${{ }} interpolation, so the value - # is never expanded into this script's source. + # KIT_VERSION arrives through env, not template interpolation, so the + # value is never expanded into this script's source. Do not write the + # literal expression syntax here either: GitHub expands it inside run + # bodies, shell comments included, and an empty one makes the whole + # workflow file fail to parse. # Force the version declared in the kit spec and make sure it exists in # the project by passing --existing-version; if it does not exist the From 573db3051361543d0c55a4a1605cc9861957df32 Mon Sep 17 00:00:00 2001 From: Miguel Martinez Trivino Date: Mon, 21 Sep 2026 15:52:51 +0200 Subject: [PATCH 2/2] fix(ci): pin a login-action that supports Docker Hub OIDC The Docker Hub login step passes the organization as `username`, omits `password` and sets DOCKERHUB_OIDC_CONNECTIONID, which is the documented Docker Hub OIDC shape. That support landed in docker/login-action v4.5.0; the step pinned v4.4.0, which ignores the variable entirely and rejects a password-less login with "Password required". Pin v4.6.0. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino Chainloop-Trace-Sessions: 1e55d1fc-a673-481e-a278-4cdd9eecb47f --- .github/workflows/package_sandbox_kit.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/package_sandbox_kit.yaml b/.github/workflows/package_sandbox_kit.yaml index 26df6dd39..3457fc47c 100644 --- a/.github/workflows/package_sandbox_kit.yaml +++ b/.github/workflows/package_sandbox_kit.yaml @@ -128,8 +128,11 @@ jobs: # governed by the connection's ruleset, which matches the subject claim # repo:chainloop-dev/chainloop:ref:refs/heads/main - adding an `environment:` # to this job would change that claim and stop it matching. + # Docker Hub OIDC landed in login-action v4.5.0; anything older ignores + # DOCKERHUB_OIDC_CONNECTIONID and fails with "Password required", so this + # pin must not be moved backwards. - name: Docker login to Docker Hub - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 env: DOCKERHUB_OIDC_CONNECTIONID: 361a9222-f648-4f62-baf4-5f500f7fbf54 with: