Files
HugoBlox-kit/.github/workflows/devcontainer-image.yml
T
George Cushen 6aa2898258 chore(deps): upgrade to Hugo v0.161.0 (css.TailwindCSS Node.js sandbox)
Hugo v0.161 dropped the standalone tailwindcss binary; @tailwindcss/cli
npm package is now the only accepted transformer, invoked via
`node --permission` (Node >= 22 required).

- Bump module.hugoVersion.min to 0.161.0 in modules/blox/hugo.yaml;
  add comment explaining why security.node.permissions is left to
  Hugo's built-in defaults
- Bump hugo_version / HUGO_VERSION / devcontainer image tag to 0.161.0
  across all 9 templates (hugoblox.yaml, netlify.toml, devcontainer.json)
- Bump devcontainer base image Node 20 → 22 and default Hugo version
- Add scripts/check-template-deps.mjs to assert every template declares
  tailwindcss + @tailwindcss/cli; wire as pnpm check:template-deps
- Harden CI: new audit-template-deps job gates all build jobs; add
  `require.resolve('@tailwindcss/cli/package.json')` check after each
  pnpm install to catch the exact "binary is not a Node.js script" failure
2026-04-30 20:12:37 +01:00

88 lines
2.4 KiB
YAML

name: Build HugoBlox devcontainer image
on:
push:
branches: [main]
paths:
- ".devcontainer/base.Dockerfile"
- ".github/workflows/devcontainer-image.yml"
workflow_dispatch:
inputs:
hugo_versions:
description: "Comma-separated Hugo versions to build (e.g. 0.152.2,0.154.0)"
required: false
env:
IMAGE_NAME: ghcr.io/hugoblox/hugo-blox-dev
# Hugo >= 0.161.0 requires Node >= 22 for css.TailwindCSS Node permissions.
DEFAULT_HUGO_VERSION: 0.161.0
NODE_VERSION: 22
PNPM_VERSION: 10.14.0
jobs:
prepare-matrix:
runs-on: ubuntu-latest
outputs:
versions: ${{ steps.versions.outputs.matrix }}
steps:
- name: Select Hugo versions
id: versions
env:
VERSIONS: ${{ github.event.inputs.hugo_versions || env.DEFAULT_HUGO_VERSION }}
run: |
MATRIX=$(python - <<'PY'
import os, json
versions = [v.strip() for v in os.environ["VERSIONS"].split(",") if v.strip()]
print(json.dumps(versions))
PY
)
echo "matrix=${MATRIX}" >> "$GITHUB_OUTPUT"
build-and-push:
needs: prepare-matrix
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
hugo: ${{ fromJson(needs.prepare-matrix.outputs.versions) }}
steps:
- name: Checkout
uses: actions/checkout@v6
- name: Log in to GHCR
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Compute tags
id: tags
env:
HUGO_VERSION: ${{ matrix.hugo }}
run: |
TAGS="${IMAGE_NAME}:hugo${HUGO_VERSION}"
if [ "${HUGO_VERSION}" = "${DEFAULT_HUGO_VERSION}" ]; then
TAGS="${TAGS}\n${IMAGE_NAME}:latest"
fi
{
echo "list<<EOF"
printf "%b\n" "$TAGS"
echo "EOF"
} >> "$GITHUB_OUTPUT"
- name: Build and push image
uses: docker/build-push-action@v7
with:
context: .
file: .devcontainer/base.Dockerfile
push: true
build-args: |
HUGO_VERSION=${{ matrix.hugo }}
NODE_VERSION=${{ env.NODE_VERSION }}
PNPM_VERSION=${{ env.PNPM_VERSION }}
tags: ${{ steps.tags.outputs.list }}