Skip to content

fix(ci): install oras 1.3.4 from its release URL and checksum - #27

Merged
tmccoy14 merged 1 commit into
mainfrom
fix/oras-1.3.4-install
Sep 24, 2026
Merged

tmccoy14 merged 1 commit into
mainfrom
fix/oras-1.3.4-install

Conversation

@tmccoy14

Copy link
Copy Markdown
Contributor

Summary

The mirror-transport job in Helm CI, and both oras steps in the Cloudsmith mirror workflow, fail with:

Error: official ORAS CLI releases does not contain version 1.3.4

The pinned oras-project/setup-oras (v1, 22ce207) resolves versions from a bundled release list that ends at 1.3.0; even the latest action (v2.0.1) only lists up to 1.3.3. oras 1.3.4 was released 2026-08-27.

This passes the official 1.3.4 linux_amd64 release URL and its SHA-256 (from oras_1.3.4_checksums.txt) to the three setup-oras steps. When both url and checksum are set, the action skips the version list and still verifies the download against the checksum.

These jobs had not run before now: oras-project/setup-oras, sigstore/cosign-installer, and cloudsmith-io/cloudsmith-cli-action were missing from the org actions allowlist, so Helm CI failed at startup since #25 merged. They were added to the allowlist today.

Test plan

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@tmccoy14
tmccoy14 merged commit 819e388 into main Sep 24, 2026
2 checks passed
@tmccoy14
tmccoy14 deleted the fix/oras-1.3.4-install branch September 24, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants