From ac61265ea0420380b7b8eaebc5c65d7ac7f75176 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 29 Aug 2026 12:00:03 +1000 Subject: [PATCH] Route LDAP plugin through artifactapi remote for secure image builds. Replace direct repo.jellyfin.org download with artifactapi.k8s.syd1.au.unkin.net remote. SHA256 pin guarantees integrity over HTTP. Both plugins now consistent in sourcing from artifactapi infrastructure. --- Dockerfile.runtime | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/Dockerfile.runtime b/Dockerfile.runtime index 61b009c..9abef84 100644 --- a/Dockerfile.runtime +++ b/Dockerfile.runtime @@ -35,10 +35,11 @@ RUN apt-get update \ && apt-get install -y --no-install-recommends curl ca-certificates unzip \ && rm -rf /var/lib/apt/lists/* -ARG LDAP_URL=https://repo.jellyfin.org/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip +ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip ARG LDAP_SHA256=c2386c001be439c9946280a02d62610f29e325d4094e83bd31221de3f7aa20ae -# SSO is served through the artifactapi github proxy, which the CI build network -# can reach (github is not directly reachable). SSO_SHA256 pins the exact bytes. +# LDAP is served through artifactapi remote. SSO is served through the artifactapi +# github proxy, which the CI build network can reach (github is not directly reachable). +# SHA256 pins match each release's published asset for reproducibility and integrity. ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107