From e3810145343bed96ebc46a672544e589457d0b97 Mon Sep 17 00:00:00 2001 From: Hrabovszki1023 Date: Fri, 7 Aug 2026 10:53:10 +0200 Subject: [PATCH] Remove privileged Docker Hub metadata sync --- .github/workflows/docker-publish.yml | 18 ------------------ docs/contracts/version-0.1.md | 7 ++++--- tests/unit/test_docker_publish_workflow.py | 4 +--- 3 files changed, 5 insertions(+), 24 deletions(-) diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 8da146c..dd611da 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -125,21 +125,3 @@ jobs: PYLONTECH_BUILD_REVISION=${{ github.sha }} cache-from: type=gha cache-to: type=gha,mode=max - - dockerhub-description: - name: Update Docker Hub overview - needs: image - if: github.event_name == 'push' - runs-on: ubuntu-latest - steps: - - name: Check out repository - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 - - - name: Synchronize README to Docker Hub - uses: peter-evans/dockerhub-description@e98e4d1628a5f3be2be7c231e50981aee98723ae # v4.0.0 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - repository: ${{ env.IMAGE_NAME }} - short-description: Read-only Pylontech monitoring with REST, MQTT and cell-voltage heatmaps - enable-url-completion: true diff --git a/docs/contracts/version-0.1.md b/docs/contracts/version-0.1.md index d45707e..f606378 100644 --- a/docs/contracts/version-0.1.md +++ b/docs/contracts/version-0.1.md @@ -705,9 +705,10 @@ the health payload shall not make the container unhealthy and shall not trigger a restart loop during a temporary external outage. The GitHub README shall provide a complete install, verification, update and -uninstall example for the published image. The same README shall be synchronized -to the Docker Hub repository overview after a successful `main` or version-tag -image publication, using the existing Docker Hub credentials. +uninstall example for the published image. The Docker Hub repository overview +shall contain the same installation example and may be maintained manually. +Updating repository metadata shall not require granting the image-publishing +token permission to delete Docker Hub content. The Waveshare raw TCP console is unencrypted and shall be deployed on a dedicated isolated technical network or VLAN. Firewall policy shall permit diff --git a/tests/unit/test_docker_publish_workflow.py b/tests/unit/test_docker_publish_workflow.py index 006ad5a..be7d3c0 100644 --- a/tests/unit/test_docker_publish_workflow.py +++ b/tests/unit/test_docker_publish_workflow.py @@ -15,7 +15,7 @@ def test_docker_publish_workflow_is_valid_yaml() -> None: assert document["name"] == "Verify and publish Docker image" assert document["permissions"] == {"contents": "read"} - assert set(document["jobs"]) == {"verify", "image", "dockerhub-description"} + assert set(document["jobs"]) == {"verify", "image"} def test_docker_publish_workflow_has_safe_events_and_credentials() -> None: @@ -30,8 +30,6 @@ def test_docker_publish_workflow_has_safe_events_and_credentials() -> None: assert "${{ secrets.DOCKERHUB_TOKEN }}" in text assert "hrabovszki/pylontech-console" in text assert "platforms: linux/amd64" in text - assert "Update Docker Hub overview" in text - assert "enable-url-completion: true" in text def test_docker_publish_workflow_reserves_latest_for_stable_tags() -> None: