Skip to content

ci: stop publishing the legacy FIPS images (#48) - #49

Merged
Xavier Fournet (xfournet) merged 1 commit into
mainfrom
issue/48-stop-legacy-images
Oct 1, 2026
Merged

Xavier Fournet (xfournet) merged 1 commit into
mainfrom
issue/48-stop-legacy-images

Conversation

@xfournet

Copy link
Copy Markdown
Member

Proposed changes

  • Delete .github/workflows/docker-build-push-legacy.yml and legacy/, which built filigran/python-fips and filigran/python-nodejs-fips.
  • Drop the paths-ignore: legacy/** filters from the main workflow.
  • Drop the Renovate custom managers for the OpenSSL and CPython pins, along with the python/cpython version rule that constrained them — nothing else declares those dependencies.
  • Replace the README migration section with a short note: the previous images are no longer published, stay pullable at their last build, and are replaced by the alpine-prefixed ones.

Related issues

How to test this PR

The main workflow runs on this pull request and builds both images without publishing them. Nothing in the repository references legacy/ any more:

grep -rn legacy . --exclude-dir=.git

Checklist

  • The PR title follows the Conventional Commits convention type(scope?): description (#issue)
  • I signed my commits
  • This PR is linked to an issue
  • I consider the submitted work as finished
  • I tested the code for its functionality
  • I added/updated the relevant documentation
  • Where necessary, I refactored code to improve the overall quality

Further comments

The nine Dockerfile_fips in OpenCTI-Platform that used the previous images — opencti-platform, opencti-worker and seven internal connectors — already reference the new names on their default branches. Once this is merged, filigran/python-fips and filigran/python-nodejs-fips stop receiving updates.

🤖 Generated with Claude Code

Every known consumer now references filigran/alpine-python-fips and
filigran/alpine-python-nodejs-fips, so the migration window kept open by the
legacy workflow closes. The workflow, legacy/ and the Renovate managers for the
OpenSSL and CPython pins that only those Dockerfiles used are removed, and the
README notes that the previous images are no longer published.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:04
@xfournet Xavier Fournet (xfournet) added filigran team Item from the Filigran team. vibe-coded PR: AI-assisted change — the author reviews it before requesting others' review. labels Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The legacy build path and its references are consistently removed, matching issue #48 and the PR description.

Review effort: Balanced
Findings: None

What changed in this PR

Retires legacy FIPS image publishing after consumers migrated to Alpine-prefixed images.

Changes:

  • Removes legacy Dockerfiles, OpenSSL configuration, and publishing workflow.
  • Removes obsolete Renovate rules and workflow path exclusions.
  • Documents legacy image retirement and replacements.
File Description
.github/​workflows/​docker-build-push-legacy.yml Removes legacy publishing workflow.
.github/​workflows/​docker-build-push.yml Runs for all repository changes.
legacy/​Dockerfile_python Removes legacy Python image.
legacy/​Dockerfile_python_nodejs Removes legacy Python/Node.js image.
legacy/​openssl.cnf Removes legacy OpenSSL configuration.
renovate.json5 Removes legacy dependency managers and rule.
README.md Documents retired images and replacements.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@xfournet
Xavier Fournet (xfournet) merged commit 33e5e62 into main Oct 1, 2026
3 checks passed
@xfournet
Xavier Fournet (xfournet) deleted the issue/48-stop-legacy-images branch October 1, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

filigran team Item from the Filigran team. vibe-coded PR: AI-assisted change — the author reviews it before requesting others' review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: stop publishing the legacy FIPS images

2 participants