### pinned download verification # Command (from repository root): docker build --build-arg DOLTGRES_VERSION=0.57.3 -t doltgres-release-download:qa . # Build-time version check: Doltgres version 0.57.3 # Command: docker run --rm --entrypoint /usr/local/bin/doltgres doltgres-release-download:qa --version # Runtime version: Doltgres version 0.57.3 ### stale download verification # Command (from repository root): docker build --build-arg DOLTGRES_VERSION=0.57.1 -t doltgres-release-stale:qa . && docker run --rm --entrypoint /usr/local/bin/doltgres doltgres-release-stale:qa --version # Raw result: image build succeeded; build-time check printed Doltgres version 0.57.1; runtime printed Doltgres version 0.57.1. # Expected behavior was rejection of stale binary, but Dockerfile published it successfully. ### source path evidence # Dockerfile lines 40-43 download install.sh for an explicit release, without passing an expected binary version or checking the installed binary afterward. RUN if [ "$DOLTGRES_VERSION" != "latest" ] && [ "$DOLTGRES_VERSION" != "source" ]; then \ echo "fetching https://github.com/dolthub/doltgresql/releases/download/v${DOLTGRES_VERSION}/install.sh"; \ curl -L "https://github.com/dolthub/doltgresql/releases/download/v${DOLTGRES_VERSION}/install.sh" | bash; \ fi # Dockerfile lines 48-51 only execute --version as a smoke check; the output is not compared with DOLTGRES_VERSION. COPY --from=download-binary /usr/local/bin/doltgres* /usr/local/bin/ RUN /usr/local/bin/doltgres --version # scripts/install.sh lines 102-112 install the archive contents without a post-download identity assertion. install_binary_release() { local FILE="doltgresql-$PLATFORM_TUPLE.tar.gz" local URL="$RELEASES_BASE_URL/$FILE" curl -A "$CURL_USER_AGENT" -fsL "$URL" > "$FILE" tar zxf "$FILE" install -o 0 -g 0 "doltgresql-$PLATFORM_TUPLE/bin/doltgres" /usr/local/bin } ### final result # final result: RELEASE-3 failed - pinned 0.57.3 passed, but a stale 0.57.1 executable was accepted and published instead of being rejected.