diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 714dad0c0e..0f5f0318f8 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -52,6 +52,8 @@ jobs: - uses: actions/setup-node@v7 with: node-version: 24 + - name: Resolve branch manifest changes before the frozen install + run: pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile - run: pnpm install --frozen-lockfile - name: Build matching migrator artifacts env: diff --git a/docker/daytona-runner/Dockerfile b/docker/daytona-runner/Dockerfile index 4e093bf10f..1de606b4fa 100644 --- a/docker/daytona-runner/Dockerfile +++ b/docker/daytona-runner/Dockerfile @@ -28,7 +28,7 @@ COPY cli/package.json ./cli/package.json # The complete resolved lock (including transitive integrity hashes) is reviewed. # Reject registry-time drift BEFORE installing packages or running lifecycle code. # Refresh this digest together with source/provider dependency changes. -ARG PAPERCLIP_RUNNER_LOCK_SHA256=72faa8db55c9e0d3287c73e9f9bfff116d71ea435426db81df24ffed32794cfb +ARG PAPERCLIP_RUNNER_LOCK_SHA256=84409576c7cbd2bec50b535c6df6acf3691bdec7c7697e6c50b2fb834b56f203 RUN pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile \ && printf '%s pnpm-lock.yaml\n' "${PAPERCLIP_RUNNER_LOCK_SHA256}" > /tmp/provider-lock.sha256 \ && sha256sum -c /tmp/provider-lock.sha256 \