feat: pin the database container to PostgreSQL 18.6 (E00-S03-T01)

- compose.yaml: db.image pinned to postgres:18.6-bookworm (exact 18.6 minor,
  same bookworm flavor, no Alpine drift) so the database container is
  reproducible and exposes the expected PostgreSQL version; document the
  rollback (revert image to postgres:18-bookworm)
- .gitea/workflows/ci.yml: new compose-config job runs
  tests/compose-config.test.mjs on every PR so the pinned-version criterion
  gates merges (docker-gated real-stack probes skip cleanly without a daemon)
This commit is contained in:
implementer
2026-08-29 10:45:00 +00:00
parent 38c17f0e7a
commit 4cd68c9193
2 changed files with 24 additions and 4 deletions
+17
View File
@@ -36,3 +36,20 @@ jobs:
node-version: '24'
- name: Run secrets-not-embedded test suite
run: node --test tests/secrets-not-embedded.test.mjs
# E00-S03-T01: the static assertions of tests/compose-config.test.mjs (db
# image pinned to postgres:18.6-bookworm, health gate, volume persistence,
# build platforms) gate every PR (the docker-gated real-stack probes inside
# the same file run where a Docker daemon is available and skip cleanly
# otherwise).
compose-config:
name: Compose config (E00-S03-T01)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Node.js 24
uses: actions/setup-node@v4
with:
node-version: '24'
- name: Run compose-config test suite
run: node --test tests/compose-config.test.mjs