diff --git a/scripts/publish-container.sh b/scripts/publish-container.sh index 650836528e..54cf64c60f 100644 --- a/scripts/publish-container.sh +++ b/scripts/publish-container.sh @@ -62,7 +62,7 @@ for target in "$image-migrations" "$image"; do # Import may change compression/manifest representation, but the immutable # image config digest must still match the exact local image we verified. expected_config="$(docker image inspect --format '{{.Id}}' "$target")" - remote_config="$(regctl manifest get "$target" --format '{{.GetConfig.Digest}}')" + remote_config="$(regctl manifest get "$target" --platform "linux/$arch" --format '{{.GetConfig.Digest}}')" [[ "$remote_config" = "$expected_config" ]] || { echo "Published image config does not match verified local image" >&2; exit 1; } rm -f -- "$context/image.tar" done diff --git a/src/lib/publish-container.test.ts b/src/lib/publish-container.test.ts index d873ca06cc..40fbbfd5eb 100644 --- a/src/lib/publish-container.test.ts +++ b/src/lib/publish-container.test.ts @@ -89,6 +89,7 @@ it("bounds uploads and verifies both published image configs", () => { expect(calls).not.toContain("docker push"); expect(calls.match(/regctl image import/g)).toHaveLength(2); expect(calls.match(/regctl manifest get/g)).toHaveLength(2); + expect(calls.match(/--platform linux\/amd64/g)).toHaveLength(2); }); it.each(["upload-fails", "wrong-config", "bad-checksum"])( "stops publication on %s",