From 7d6e52537a26a3ebe789a901a8fbb8151f9130fb Mon Sep 17 00:00:00 2001 From: archipelago Date: Mon, 17 Aug 2026 10:54:05 -0400 Subject: [PATCH] chore(apps): bump the pins that can move without mirroring MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Of the 33 apps behind upstream, these five pull straight from a public registry, so their targets exist already and the bump is real work rather than a promise: strfry 1.0.4 -> 1.1.1 netbird (nginx) 1.27-alpine -> 1.31.3-alpine pine (nginx) 1.27-alpine -> 1.31.3-alpine pine-piper 2.2.2 -> 2.4.2 nostr-rs-relay 0.8.9 -> 0.10.0 All five targets verified present upstream with skopeo before editing, so none of these can turn into an image-not-found on a node. Deliberately NOT bumped here, though they are also direct-pull: core-lightning (v23.08 -> v26.06, ~3 years of schema migrations), gitea (four minors of DB migrations), and netbird-server/netbird-dashboard — which have to move in lockstep and carry their own migrations. Those are each a piece of work, not a line edit. The other 24 are blocked on something else entirely: their images live in our mirror and none of the upgrade targets have been mirrored yet, so a pin bump alone would break every install. That needs registry push credentials. These take effect when the catalog is regenerated and re-signed — the catalog overrides on-disk manifests, so editing here changes nothing on a node until the signing ceremony. Co-Authored-By: Claude Opus 5 (1M context) --- apps/netbird/manifest.yml | 2 +- apps/nostr-rs-relay/manifest.yml | 4 ++-- apps/pine-piper/manifest.yml | 4 ++-- apps/pine/manifest.yml | 2 +- apps/strfry/manifest.yml | 4 ++-- 5 files changed, 8 insertions(+), 8 deletions(-) diff --git a/apps/netbird/manifest.yml b/apps/netbird/manifest.yml index 92a204e0..c64c28fe 100644 --- a/apps/netbird/manifest.yml +++ b/apps/netbird/manifest.yml @@ -18,7 +18,7 @@ app: container_name: netbird container: - image: docker.io/library/nginx:1.27-alpine + image: docker.io/library/nginx:1.31.3-alpine pull_policy: if-not-present network: netbird-net # Self-signed TLS cert materialised before create — the dashboard needs a diff --git a/apps/nostr-rs-relay/manifest.yml b/apps/nostr-rs-relay/manifest.yml index e8df12ad..69687072 100644 --- a/apps/nostr-rs-relay/manifest.yml +++ b/apps/nostr-rs-relay/manifest.yml @@ -1,7 +1,7 @@ app: id: nostr-rs-relay name: Nostr Relay (Rust) - version: 0.8.0 + version: 0.10.0 # Where this app comes from, so scripts/check-upstream-releases.py can # tell us when the pin below has fallen behind. Without it nothing can: # container.image names our mirror, not the project it was mirrored from. @@ -11,7 +11,7 @@ app: description: High-performance Nostr relay written in Rust. Host your own decentralized social media relay and earn networking profits. container: - image: scsibug/nostr-rs-relay:0.8.9 + image: scsibug/nostr-rs-relay:0.10.0 image_signature: cosign://... pull_policy: verify-signature data_uid: "1000:1000" diff --git a/apps/pine-piper/manifest.yml b/apps/pine-piper/manifest.yml index 709b6d8d..5b383e1f 100644 --- a/apps/pine-piper/manifest.yml +++ b/apps/pine-piper/manifest.yml @@ -1,7 +1,7 @@ app: id: pine-piper name: Pine Piper (TTS) - version: "2.2.2" + version: "2.4.2" # Where this app comes from, so scripts/check-upstream-releases.py can # tell us when the pin below has fallen behind. Without it nothing can: # container.image names our mirror, not the project it was mirrored from. @@ -18,7 +18,7 @@ app: container_name: pine-piper container: - image: docker.io/rhasspy/wyoming-piper:2.2.2 + image: docker.io/rhasspy/wyoming-piper:2.4.2 pull_policy: if-not-present network: archy-net network_aliases: [pine-piper] diff --git a/apps/pine/manifest.yml b/apps/pine/manifest.yml index a8cfd7b8..44bf1729 100644 --- a/apps/pine/manifest.yml +++ b/apps/pine/manifest.yml @@ -19,7 +19,7 @@ app: container_name: pine container: - image: docker.io/library/nginx:1.27-alpine + image: docker.io/library/nginx:1.31.3-alpine pull_policy: if-not-present network: archy-net network_aliases: [pine] diff --git a/apps/strfry/manifest.yml b/apps/strfry/manifest.yml index 0dde8a64..7a69380b 100644 --- a/apps/strfry/manifest.yml +++ b/apps/strfry/manifest.yml @@ -1,7 +1,7 @@ app: id: strfry name: Strfry Nostr Relay - version: 0.9.0 + version: 1.1.1 # Where this app comes from, so scripts/check-upstream-releases.py can # tell us when the pin below has fallen behind. Without it nothing can: # container.image names our mirror, not the project it was mirrored from. @@ -11,7 +11,7 @@ app: description: Lightweight Nostr relay written in C++. Alternative to nostr-rs-relay with lower resource usage. container: - image: dockurr/strfry:1.0.4 + image: dockurr/strfry:1.1.1 image_signature: cosign://... pull_policy: verify-signature