Skip to content

Invoke the CLI directly instead of through a shell - #3

Merged
jochenchrist merged 2 commits into
mainfrom
fix/shell-less-image
Aug 14, 2026
Merged

jochenchrist merged 2 commits into
mainfrom
fix/shell-less-image

Conversation

@jochenchrist

@jochenchrist jochenchrist commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

The action is broken for every consumer since datacontract/cli:latest was rebuilt on 2026-08-04. The image moved to a shell-less Docker Hardened Image base, and this action's entrypoint: /bin/sh fails before the CLI runs:

docker: Error response from daemon: failed to create task for container:
OCI runtime create failed: exec: "/bin/sh": stat /bin/sh: no such file or directory

The shell-less base is deliberate (see the CLI's Dockerfile and the 1.1.0 changelog), so the action has to stop depending on a shell.

Change

entrypoint is now datacontract and the command is a plain arg list. The released CLI (1.1.1) rejects an empty --publish value (datacontract/datacontract-cli#1491 is still open) and the runner passes empty args as literal "" instead of dropping them, so the publish option is a single conditional --publish=<url> arg that degrades to --no-logs (the CLI's default behavior anyway) when the input is unset. The action's inputs are unchanged.

This also adds a smoke-test workflow that runs the action against a contract with a local CSV server on every push, so a base-image change in the CLI repo can no longer break the action silently.

Verified

  • Smoke test on this branch is green with today's datacontract/cli:latest (1.1.1): the runner starts the container with --entrypoint datacontract, all 4 checks pass, and the JUnit report is written.
  • The publish path was tested locally against an HTTP sink: --publish=<url> runs the tests and POSTs the results with the API key header attached; leaving publish empty runs the tests without publishing.

datacontract/cli 1.1.0 moved to a shell-less hardened base image, so the
/bin/sh entrypoint fails the container before the CLI runs:

  OCI runtime create failed: exec: "/bin/sh": stat /bin/sh: no such file
  or directory

The entrypoint is now the CLI itself with a plain arg list. Since an arg
list cannot drop an entry conditionally, --publish is always passed and an
empty value means no publish (datacontract-cli#1491).
The released CLI (1.1.1) rejects an empty --publish value and the runner
passes empty args as literal "" instead of dropping them, so always
passing the flag breaks the default no-publish case. The publish option
is now a single conditional `--publish=<url>` arg that degrades to
`--no-logs` (the CLI default anyway) when the input is unset.

The smoke-test workflow runs the action against a local CSV contract on
every push, covering the shell-less invocation end to end.
@jochenchrist
jochenchrist marked this pull request as ready for review August 14, 2026 14:33
@jochenchrist
jochenchrist merged commit 2e8d136 into main Aug 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant