Skip to content

build: pin pixi version in images/Dockerfile - #261

Open
InessaPawson wants to merge 1 commit into
nebari-dev:mainfrom
InessaPawson:243-pin-pixi-version
Open

InessaPawson wants to merge 1 commit into
nebari-dev:mainfrom
InessaPawson:243-pin-pixi-version

Conversation

@InessaPawson

Copy link
Copy Markdown

What does this implement/fix?

Pins the pixi version installed in images/Dockerfile.

Previously the installer ran unpinned, so every image build picked up whatever the latest pixi release was that day. A pixi minor bump can change lock handling or resolution behaviour with no corresponding change in this repo, making builds non-reproducible.

This PR:

  • Adds a PIXI_VERSION build arg (currently v0.81.0) in the builder stage and passes it to the installer, so the version is explicit and bumped deliberately.
  • Adds a post-install check (pixi --version | grep -qF "${PIXI_VERSION#v}") that fails the build if the installed binary doesn't match the pin.

No other lines change. Later stages still copy /usr/local/bin/pixi from the builder as before.

Not included: automated bumps. Dependabot's docker ecosystem only tracks FROM images, not build args, so keeping this current would need a Renovate custom regex manager. Happy to open that as a follow-up if wanted.

Closes #243.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds a feature)
  • Breaking change (fix or feature that would cause existing features not to work as expected)
  • Documentation Update
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes, no API changes)
  • Build related changes
  • Other (please describe)

Testing

  • Did you test the pull request locally?
  • Did you add new tests?

Text styling

  • The content is written with plain language (where relevant).
  • If there are headers, they use the proper header tags (with only one level-one header: H1 or # in markdown).
  • All links describe where they link to (for example, check the Nebari website).
  • This content adheres to the Nebari style guides.

Non-text content

  • All content is represented as text (for example, images need alt text, and videos need captions or descriptive transcripts).
  • If there are emojis, there are not more than three in a row.
  • Don't use flashing GIFs or videos.
  • If the content were to be read as plain text, it still makes sense, and no information is missing.

@pmeier

pmeier commented Oct 9, 2026

Copy link
Copy Markdown
Member

Thanks Inessa!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin pixi version in images/Dockerfile

2 participants