fix(runner): refresh Daytona integrity pin after master patch updates

Use the reviewed resolved lock hash with master ACPX and postgres patches. Keep the immutable integrity check and leave the bot-owned lockfile unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
Dotta
2026-09-18 22:13:16 -05:00
co-authored by Paperclip
parent f20ccfb38a
commit 4e75881db6
+1 -1
View File
@@ -28,7 +28,7 @@ COPY cli/package.json ./cli/package.json
# The complete resolved lock (including transitive integrity hashes) is reviewed.
# Reject registry-time drift BEFORE installing packages or running lifecycle code.
# Refresh this digest together with source/provider dependency changes.
ARG PAPERCLIP_RUNNER_LOCK_SHA256=af3b879fea127a608b0f9279627f357638299441bbf41835f0b91ab0162e441c
ARG PAPERCLIP_RUNNER_LOCK_SHA256=133cc415964e4ee3f348251c315d560cc8f8f51a8dddde2da84e065ba4ae3fa6
RUN pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile \
&& printf '%s pnpm-lock.yaml\n' "${PAPERCLIP_RUNNER_LOCK_SHA256}" > /tmp/provider-lock.sha256 \
&& sha256sum -c /tmp/provider-lock.sha256 \