## Summary
The showcase image drift detection compared image tags against `main`
HEAD SHA, but deploys only trigger when `showcase/` or
`examples/integrations/` paths change. Any non-showcase commit to main
(package bumps, workflow changes, docs, etc.) made ALL images appear
stale, triggering unnecessary rebuild workflows and Slack alerts.
## Root Cause
```bash
# Before: always stale after non-showcase commits
MAIN_SHA=$(git ls-remote ... main | cut -f1)
```
## Fix
Query the GitHub API for the last commit that actually touched
showcase-related paths, then check image tags against those SHAs:
```bash
SHOWCASE_SHA=$(gh api "repos/.../commits?path=showcase&per_page=1" --jq '.[0].sha')
EXAMPLES_SHA=$(gh api "repos/.../commits?path=examples/integrations&per_page=1" --jq '.[0].sha')
# Image is up-to-date if it matches EITHER SHA
```
## Impact
- No more false-positive drift alerts flooding #oss-alerts
- No more unnecessary rebuild triggers for every non-showcase commit
- Drift detection now only fires when showcase code actually changed but
images weren't rebuilt
🤖 Generated with [Claude Code](https://claude.com/claude-code)
The drift check compared image tags against main HEAD SHA, but deploys
only trigger when showcase/ or examples/integrations/ paths change. Any
non-showcase commit to main made ALL images appear stale, triggering
unnecessary rebuild workflows and Slack alerts.
Fix: query the GitHub API for the last commit that touched each path
and check image tags against those SHAs instead.
Replaced 23 identical build jobs with one parameterized matrix job.
1200 lines to ~250. Service config as JSON, matrix generated from
path-filter results. Shell special cases (LFS, build-args, custom
Dockerfile) handled via matrix properties and dedicated prep step.
Merged standalone commitlint into static_quality as 4th parallel job.
Upgraded all actions to v4, added concurrency group. Format job now
auto-fixes and commits back to same-repo PR branches. Commitlint
posts helpful PR comment with valid prefixes on failure.
publish-commit had no path/branch filters — fired on every push.
Restricted to packages/**, upgraded checkout to v4, added pnpm
cache and --frozen-lockfile to both publish workflows.
## Summary
Adds an image drift check to the 6-hourly drift detection workflow. For
each showcase service, compares the GHCR `:latest` image digest against
the image tagged with the current main HEAD SHA. If they don't match,
the service's image is stale (main has code that hasn't been
built/deployed).
Posts to #oss-alerts when stale images are detected:
```
📦 Image Drift Detected
⚠️ ms-agent-dotnet — GHCR image not built for current main
```
This catches the scenario where a merge to main changes showcase code
but the deploy workflow misses it due to timing/cancellation.
The changesets/action@v1 writes auth to ~/.npmrc but
actions/setup-node sets NPM_CONFIG_USERCONFIG to a temp path,
causing pnpm to read a different .npmrc during publish. All packages
fail with E404 on PUT because the auth token isn't picked up.
This adds an explicit `npm config set` step that writes the literal
token to whichever file NPM_CONFIG_USERCONFIG points at.
https://claude.ai/code/session_01KnUcvcGEthP64SKk98HzJ6