Use source revisions for non-release Docker builds - #3357
Merged
SamMorrowDrums merged 1 commit intoOct 1, 2026
Merged
Conversation
Only tag builds should supply a release version. Other Docker builds use the existing linked-commit fallback instead of treating a branch or pull-request ref name as a release. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 6dde41da-ec25-4370-b26c-b036d0a53b3c
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The workflow change correctly preserves release tags while allowing non-tag builds to resolve the embedded commit revision.
Review effort: Balanced
Findings: None
What changed in this PR
Ensures non-release Docker builds report their source revision rather than a branch name.
Changes:
- Supplies tag names as versions only for tagged builds.
- Documents Docker build-version attribution.
| File | Description |
|---|---|
.github/workflows/docker-publish.yml |
Gates release-version injection on tag refs. |
README.md |
Documents tag and source-revision behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
jidicula
force-pushed
the
jidicula/mcp-immutable-container-versions-20261001
branch
from
October 1, 2026 11:54
71f3e8a to
158205d
Compare
jidicula
marked this pull request as ready for review
October 1, 2026 12:02
SamMorrowDrums
approved these changes
Oct 1, 2026
SamMorrowDrums
deleted the
jidicula/mcp-immutable-container-versions-20261001
branch
October 1, 2026 15:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Use release-tag versions only for tagged Docker builds, so branch, nightly and pull-request builds identify their full source revision.
Why
As part of improving GraphQL observability to service teams, as well as improving our GraphQL Platform team's own observability of the platform at large, we want client services to clearly identify themselves with their service name and version. This helps us clearly attribute traffic, which aids incident troubleshooting and performance investigations.
Follow-up to #3323: branch names such as
mainwere being supplied as release versions, taking precedence over the available commit SHA.What changed
Gate the Docker
VERSIONbuild argument on the ref type and document the build behaviour.MCP impact
Prompts tested (tool changes only)
Not applicable; no tool changes.
Security / limits
Tool renaming
Lint & tests
./script/lint../script/test.Offline checks of the actual workflow expression and resulting compiled-binary headers passed. Container image publication was not exercised.
Docs