paperclip/.github
Dotta 03faa644fb
ci(runner): inspect Daytona image metadata remotely (#12795)
## Thinking Path
The reused Daytona image path already verifies the signed immutable
digest. It then downloads every filesystem layer only to read OCI config
fields. Buildx can retrieve the same config from that immutable digest
without pulling the layers. The assertions can therefore stay intact
while removing the expensive transfer.

## What Changed
- inspect the signed immutable Daytona image config through Buildx after
GHCR logout
- preserve digest, source revision, content ID, platform, user, and
provider-pack assertions
- extend the workflow contract test for the metadata-only path

## Verification
- Daytona image and workflow security tests: 10 passed
- Prettier and git diff checks passed
- observed full pull/prune cost: about 4m55s; metadata inspection: about
one second

## Risks
The current image has one runnable linux/amd64 platform plus its
attestation. A future genuinely multi-platform image would need explicit
linux/amd64 selection.

## Model Used
Codex (GPT-5)
2026-09-03 18:10:38 -05:00
..
ISSUE_TEMPLATE chore(github): expand issue forms (#7628) 2026-06-05 22:27:12 -07:00
scripts chore(lockfile): refresh pnpm-lock.yaml (#12771) 2026-09-03 11:08:34 -05:00
workflows ci(runner): inspect Daytona image metadata remotely (#12795) 2026-09-03 18:10:38 -05:00
CODEOWNERS chore: add @forgottendev to CODEOWNERS (#12501) 2026-08-29 08:05:43 -05:00
PULL_REQUEST_TEMPLATE.md fix(ci): make PR-template inline-description contract explicit (#10558) 2026-07-31 09:46:26 -07:00
dependabot.yml fix(observability): pin the Sentry browser SDK and gate the optional Sentry server peer on the exact version (#12270) 2026-08-27 07:20:03 -07:00