Tags, versions, and publication history¶
Every image has its own version in container.yaml. A version such as v1.0.0 describes the Strukturpiloten image contract and release line. It is not a promise that all bundled software has that version. In a distro-package Docker or Podman image, package revisions can change when the distribution repository changes and the image is rebuilt. typo3-phpfpm:v2.0.0 supplies a PHP runtime; it does not include TYPO3 version 2.0.0 or TYPO3 application code. Inspect the component manifest under /usr/share/strukturpiloten/, the image SBOM, and the image's own guide for installed versions.
| Reference | Movement | Use |
|---|---|---|
image@sha256:<index-digest> |
Immutable content identity | Reproducible deployments, audit, rollback |
image:run-<run>-<attempt>-sha-<commit> |
Immutable publication identity | Identify one workflow attempt |
image:sha-<commit> |
Immutable source identity for a verified build | Trace a repository revision |
image:vX.Y.Z |
Maintained alias, even at exact SemVer | Follow reviewed rebuilds of a declared image version |
image:vX.Y, image:vX |
Maintained aliases | Follow a minor or major release line |
image:latest and branch tags |
Maintained aliases | Follow successful publications on a branch |
For readable configuration and reproducible pulls, use a tag with a verified digest, for example ghcr.io/strukturpiloten/nextcloud-notifypush:v1.0.0@sha256:<verified-index-digest>. The digest fixes the content; the tag communicates the intended line. Let an update tool propose digest changes for review. Moving a tag does not update already running containers; pull and redeploy or configure an explicit auto-update policy.
Inspect the current artifact¶
Resolve a published tag to an index digest with skopeo; then compare the digest, source revision, architecture, and runtime/vulnerability evidence with the maintenance release record:
skopeo inspect --format '{{.Digest}}' docker://ghcr.io/strukturpiloten/nextcloud-notifypush:v1.0.0
skopeo inspect --raw docker://ghcr.io/strukturpiloten/nextcloud-notifypush:v1.0.0
A tag only describes its current target. GitHub's image-scoped source-version release records the original declared version; a later rebuild of the same version receives a separate <imageName>/maintenance/<runId>-<runAttempt> release with durable evidence. Do not treat one source-version release date as the date of every retained-version rebuild.
Dated registry examples¶
A public registry inspection on 2026-09-28 at 07:42 UTC resolved these aliases. This is a point-in-time tag observation, not a promise about their current targets or proof that each historical digest still receives maintenance. The full observations and evidence state are in the registry snapshot; re-resolve any tag before using it.
| Image | Aliases at the observed latest digest |
Older resolved alias and digest |
|---|---|---|
podman-5.8-rootless |
latest, main, v5, v5.8, v5.8.7 → sha256:7c5089a0895c9ba0a14876bc0369356cf368729975006ab037189a29e1d5d9ba |
v5.8.6 → sha256:1b29f88f2c58be615b7e74b58c2ede683115c934645a6d9573a10d701e74a2f7 |
podman-6.1-rootless |
latest, main, v6, v6.1, v6.1.2 → sha256:ee22811400ea82b31f0c3bf4f6530ff50465faa87bf9e201856e83b6e36ce58a |
v6.1.0 → sha256:5fe9b8068a8e40de1189b23434ba3e2b84ff4e3b576fe2a844e25582ad6b181e |
typo3-phpfpm |
latest, main, v2, v2.0, v2.0.0 → sha256:151bb805aec2a184b59626fe989613034f2547e754cca0ae00634868d213a491 |
Earlier v1.0.0, v1.0.1, and v1.0.2 each resolved to a different digest from the former image repository. |
For TYPO3, v2.0.0 is the current PHP-FPM image contract line. It does not mean TYPO3 2.0.0 is installed; the runtime has no TYPO3 application code. The historical v1.* aliases remain registry history and are not moved by this monorepo's release automation. Exact digest pinning preserves an old artifact but does not confer ongoing security support.
Read timestamps correctly¶
| Field or event | Meaning |
|---|---|
| Source commit time | When the source revision was committed; not a container build time. |
buildSucceededAt |
When the recorded build succeeded. |
publishedAt |
When selected maintained aliases first finished promotion and readback for the verified digest, if recorded by a matching immutable maintenance asset. Historical unknowns remain null. |
| Package or release activity | When an upstream package, repository, or GitHub release changed; not proof this image was rebuilt or pulled. |
observedAt |
When a registry reference was checked; the mutable tag can move later. |
Keep these values separate when comparing releases. An absent timestamp or unknown evidence means no matching record was supplied to the catalogue; do not infer a successful build or a failure from it. The operations guide describes guarded rollback of a maintained alias to a verified digest.