Repository navigation
Invoke the CLI directly instead of through a shell - #3
Merged
Merged
Conversation
datacontract/cli 1.1.0 moved to a shell-less hardened base image, so the /bin/sh entrypoint fails the container before the CLI runs: OCI runtime create failed: exec: "/bin/sh": stat /bin/sh: no such file or directory The entrypoint is now the CLI itself with a plain arg list. Since an arg list cannot drop an entry conditionally, --publish is always passed and an empty value means no publish (datacontract-cli#1491).
The released CLI (1.1.1) rejects an empty --publish value and the runner passes empty args as literal "" instead of dropping them, so always passing the flag breaks the default no-publish case. The publish option is now a single conditional `--publish=<url>` arg that degrades to `--no-logs` (the CLI default anyway) when the input is unset. The smoke-test workflow runs the action against a local CSV contract on every push, covering the shell-less invocation end to end.
jochenchrist
marked this pull request as ready for review
August 14, 2026 14:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The action is broken for every consumer since
datacontract/cli:latestwas rebuilt on 2026-08-04. The image moved to a shell-less Docker Hardened Image base, and this action'sentrypoint: /bin/shfails before the CLI runs:The shell-less base is deliberate (see the CLI's
Dockerfileand the 1.1.0 changelog), so the action has to stop depending on a shell.Change
entrypointis nowdatacontractand the command is a plain arg list. The released CLI (1.1.1) rejects an empty--publishvalue (datacontract/datacontract-cli#1491 is still open) and the runner passes empty args as literal""instead of dropping them, so the publish option is a single conditional--publish=<url>arg that degrades to--no-logs(the CLI's default behavior anyway) when the input is unset. The action's inputs are unchanged.This also adds a smoke-test workflow that runs the action against a contract with a local CSV server on every push, so a base-image change in the CLI repo can no longer break the action silently.
Verified
datacontract/cli:latest(1.1.1): the runner starts the container with--entrypoint datacontract, all 4 checks pass, and the JUnit report is written.--publish=<url>runs the tests and POSTs the results with the API key header attached; leavingpublishempty runs the tests without publishing.