Skip to content

fix(docs): unbreak Netlify build on the Noble image - #1433

Merged
jalseth merged 1 commit into
open-policy-agent:masterfrom
boranx:fix/docs-netlify-python-runtime
Sep 26, 2026
Merged

jalseth merged 1 commit into
open-policy-agent:masterfrom
boranx:fix/docs-netlify-python-runtime

Conversation

@boranx

@boranx boranx commented Sep 25, 2026

Copy link
Copy Markdown
Member

What

Bumps runtime.txt from Python 3.8 to 3.12 and the docs toolchain from mkdocs 1.3.0 / mkdocs-material 4.6.3 to 1.6.1 / 9.7.7.

Why

Netlify migrated the docs site to the Ubuntu 24.04 (Noble) build image, which installs toolchains with mise. mise verifies GitHub artifact attestations on the python-build-standalone tarballs it downloads, and CPython 3.8.20 predates attestation coverage:

mise ✗ python@3.8.20  1.3s · failed: No GitHub artifact attestations found for python@3.8.20
mise ERROR Failed to install core:python@3.8
Failed during stage 'Install dependencies': dependency_installation script returned non-zero exit code: 1

The build fails in ~4s, before the build script runs. Every deploy since 2026-09-25 07:27 UTC has failed, including the production builds for #1430, #1427 and #1428 — conftest.dev last published on 2026-09-19 and is missing all three.

mise offers MISE_PYTHON_GITHUB_ATTESTATIONS=false as an escape hatch, deliberately not used here: it disables supply-chain verification on the docs toolchain right after #1424 and #1428 added provenance attestations and SBOMs to our own releases, and keeps us on a Python that went EOL in October 2024.

Both halves are needed — bumping only runtime.txt gets past mise and then fails, since mkdocs-material 4.6.3 (2020) does not install under Python 3.12.

Netlify migrated the docs site to the Ubuntu 24.04 (Noble) build image,
which installs toolchains with mise. mise verifies GitHub artifact
attestations on the python-build-standalone tarballs it downloads, and
CPython 3.8.20 predates attestation coverage, so the pinned runtime
cannot be installed:

  mise ERROR Failed to install core:python@3.8: No GitHub artifact
  attestations found for python@3.8.20

Every Netlify deploy since 2026-09-25 07:27 UTC has failed, including
the production builds for the merges of open-policy-agent#1430, open-policy-agent#1427 and open-policy-agent#1428. The
last successful publish of conftest.dev was 2026-09-19, so the site is
missing all three.

Bump runtime.txt to 3.12 and bring the docs toolchain forward to match,
since mkdocs-material 4.6.3 (2020) does not install under Python 3.12.
No mkdocs.yml changes are needed; the codehilite extension still works
under Markdown 3.x.

Signed-off-by: boranx <boran.seref@gmail.com>
@boranx

boranx commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

#1431 should be mergeable after this goes first

@boranx
boranx requested a review from jalseth September 25, 2026 09:21
@jalseth
jalseth merged commit 96fc461 into open-policy-agent:master Sep 26, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants