Repository navigation
Fix Docker bake building from main instead of PR branch - #473
Merged
Merged
Conversation
docker/bake-action@v6 defaults to Git remote context at the workflow ref. Since pr-privileged.yml uses pull_request_target, this ref is always the base branch (main), causing every PR Docker image to contain main's code instead of the PR's changes. Adding source: . forces bake to use the locally checked-out PR code.
ghostwriternr
requested review from
aron-cf,
scuffi and
whoiskatrin
as code owners
March 9, 2026 10:15
|
whoiskatrin
approved these changes
Mar 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug
Since
pull_request_targetwas introduced in #458, every PR's Docker image has been built from the main branch instead of the PR branch. This means E2E tests always run against stale container code, forcing contributors to manually delete container configs to test their changes.Root Cause
docker/bake-action@v6defaults to Git remote context at the workflow ref. Forpull_request_target, that ref is always the base branch (main) — not the PR head. Despiteactions/checkoutcorrectly placing PR code on disk, the bake action bypasses local files and pulls source directly from main.Evidence from PR #437 CI logs:
ae42c52856f4dd(main HEAD)Fix
Add
source: .to the bake action, switching it from Git remote context to path context. This makes bake use the locally checked-out PR code, whichactions/checkoutalready places correctly.All existing CI optimizations (content-addressed Docker cache, GHCR layer cache, deploy-skip, docker-skip) are unaffected — they operate independently of the bake source parameter.