fix: use sha256 descriptor digest and keep operator errors fully sanitized

This commit is contained in:
2026-08-11 19:24:15 +02:00
parent 929f7dcc5e
commit 82b5453c88
4 changed files with 8 additions and 10 deletions
@@ -352,7 +352,8 @@ export async function renderActiveWorkspaceRuntime(options: {
const repository = new GitWorkspaceRepository(options.registryConfig);
await repository.ensureLayout();
const snapshotPath = options.registry.snapshotPath(revision.commit, revision.id);
const workspace = parseWorkspaceYaml(await readFileAsync(snapshotPath, "utf8"));
const descriptorSource = await readFileAsync(snapshotPath, "utf8");
const workspace = parseWorkspaceYaml(descriptorSource);
const rendered = renderWorkspaceRuntimeFromWorkspace({
workspace,
workspaceId: revision.id,
@@ -367,7 +368,7 @@ export async function renderActiveWorkspaceRuntime(options: {
return {
...rendered,
snapshotPath,
descriptorBlob: revision.blob,
descriptorBlob: `sha256:${createHash("sha256").update(descriptorSource).digest("hex")}`,
catalogBlob: (await repository.catalogBlob(revision.commit)).trim(),
};
}