Problem
#116 (5e7fff3) pinned four dev tools as ARGs managed by Renovate. That changed two facts, but the PR only corrected one of them:
- Rebuild cadence — corrected (root
README.md claude-code entry, claude-code/README.md:45 and :118, and a stale .hadolint.yaml comment).
- Version pinning — not corrected. Several places still tell readers these tools float at "latest", which is now false.
The gap came from auditing only for the string "daily"/cron. ralphex-fe/README.md never claimed a daily rebuild, so it never surfaced — while its version table silently became wrong.
Stale references to fix
Notes
Docs-only, so ci.yml's path filters (**/Dockerfile, **/*.sh, .github/workflows/**, .hadolint.yaml) mean no CI will run on the fix PR — that's expected, not a broken pipeline.
Verified while filing this: renovate.json5 is on master, all 7 # renovate: annotations match the custom manager's regex with correct captures, both crons are gone, and the daily builds stopped after 5e7fff3. The docs are the only loose end.
Problem
#116 (
5e7fff3) pinned four dev tools asARGs managed by Renovate. That changed two facts, but the PR only corrected one of them:README.mdclaude-code entry,claude-code/README.md:45and:118, and a stale.hadolint.yamlcomment).The gap came from auditing only for the string "daily"/
cron.ralphex-fe/README.mdnever claimed a daily rebuild, so it never surfaced — while its version table silently became wrong.Stale references to fix
ralphex-fe/README.md— Tools table listsClaude Code CLI | latest,RTK | latest (GitHub Releases),Ralphex | latest (GitHub Releases); now pinned to2.1.216/0.43.0/1.6.0.ralphex-fe/README.md— documents no rebuild trigger at all. Now that the cadence is a deliberate design, consumers of this image should see it (theclaude-codeREADME already explains it).claude-code/README.md:22— "rtk, ralphex — Always-latest from GitHub Releases … no version pinning needed in projects". The advice (don't pin these in your project's.mise.toml) still holds; the "always-latest" mechanism claim does not.claude-code/README.md:408— Build Args table saysAGENT_BROWSER_VERSION | latest(now0.32.3) and omitsRTK_VERSION,RALPHEX_VERSION,CLAUDE_CODE_VERSION, which are now real build args.claude-code/README.md:79— "dev infrastructure (rtk, ralphex, Claude Code) is pre-installed in the image at latest".README.md— "Updating Image Versions" describes only the manualworkflow_dispatchpath. Should state that the four agent tools are Renovate-managed and only Bun/Hugo remain manual.Notes
Docs-only, so
ci.yml's path filters (**/Dockerfile,**/*.sh,.github/workflows/**,.hadolint.yaml) mean no CI will run on the fix PR — that's expected, not a broken pipeline.Verified while filing this:
renovate.json5is onmaster, all 7# renovate:annotations match the custom manager's regex with correct captures, both crons are gone, and the daily builds stopped after5e7fff3. The docs are the only loose end.