Skip to content

ci: stamp commit hash and message on Pages direct-upload deploy - #23

Merged
tgwab-claude merged 1 commit into
mainfrom
ci/pages-deploy-commit-hash
Sep 16, 2026
Merged

tgwab-claude merged 1 commit into
mainfrom
ci/pages-deploy-commit-hash

Conversation

@tgwab-claude

Copy link
Copy Markdown
Collaborator

What changed

wrangler pages deploy on a direct upload (Git integration is off for this
project) does not record the shipped commit unless told to. Without
--commit-hash, CF Pages keeps reporting a stale or absent commit, and the
deploy-drift audit can flag production as "N commits behind" when the
served content is actually current.

Adds --commit-hash "$COMMIT_HASH" and --commit-message "$COMMIT_MESSAGE"
to the deploy step, sourced from github.sha and the commit/PR-title event
fields via env vars and referenced as "$VAR" in the shell script — not
interpolated directly into the run: text, since a commit message or PR
title is attacker-influenceable input and inline interpolation would be a
script-injection vector. --branch was already sourced this way for the
branch value; this PR moves it into the same env-var pattern for
consistency with the two new values.

Identical fix and identical diff shape to
MichalAFerber/audio-viewer.us#15,
the reference fix for
MichalAFerber/audio-viewer.us#14,
applied across the File Viewer family as part of the same sweep. Only
--project-name differs between repos.

What this does NOT do

Merging this does not retag the currently live deployment. Cloudflare
Pages does not retroactively stamp a commit hash onto a deployment that has
already shipped. The record corrects itself on this repo's next deploy to
main — until then, any deploy-drift read for this repo may still show the
old, untagged commit.

Verified

  • npx wrangler@4 pages deploy --help confirms --commit-hash and
    --commit-message are supported flags on the installed wrangler major
    (v4).
  • This repo's deploy.yml matches the reference repo's pre-fix shape
    exactly (direct upload, wrangler@4, --branch computed from
    github.ref/github.head_ref, --commit-dirty=false, gated on
    CLOUDFLARE_API_TOKEN) — only --project-name differs.
  • YAML parses (python3 -c "import yaml; yaml.safe_load(...)").
  • Diff is minimal and structurally identical to the reference PR: only the
    deploy step's env:/run: block changed.

Not verified

  • Did not run wrangler pages deploy against production — out of bounds
    for this sweep (no deploys).
  • Did not re-run the deploy-drift audit against a new deployment for this
    repo (none has shipped yet with this fix).

🤖 Generated with Claude Code

https://claude.ai/code/session_01XE6Up1JPpFrhM5tC8hvHDE

wrangler pages deploy on a direct upload does not record the shipped
commit unless told to, so the deploy-drift audit can report a repo as
behind when the content is current (see MichalAFerber/audio-viewer.us#14).
Adds --commit-hash and --commit-message, sourced from github.sha and the
commit/PR-title event fields, passed through env vars and referenced with
"$VAR" rather than interpolated into the run: text, since a commit message
or PR title is attacker-influenceable.

Same fix as MichalAFerber/audio-viewer.us#15, applied identically across
the File Viewer family.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XE6Up1JPpFrhM5tC8hvHDE
@tgwab-claude
tgwab-claude merged commit 470e4bc into main Sep 16, 2026
2 checks passed
@tgwab-claude
tgwab-claude deleted the ci/pages-deploy-commit-hash branch September 16, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants