From a7f834ef1b00126172c47041eca259d4b762b7a0 Mon Sep 17 00:00:00 2001 From: ru-sh Date: Fri, 18 Sep 2026 10:28:27 +0400 Subject: [PATCH 1/2] Publish releases within the organization only Nothing in CI pushes outside MotusLabs any more. The npm and AUR jobs are gone, the Docker job pushes to this repository's ghcr.io namespace instead of Docker Hub and ghcr.io/coder, and the codecov upload no longer sends coverage to a third party. The update and helm-chart PRs open against this repository rather than upstream. Both publish jobs also downloaded their release assets from coder/code-server, so publishing would have shipped upstream's build under this organization's name. They now read this repository's own release. install.sh, the Docker build and the Helm chart all follow, so what they install is this fork's build, patches included. --- .github/codecov.yml | 31 -------- .github/workflows/build.yaml | 5 -- .github/workflows/publish.yaml | 111 ++++++---------------------- .github/workflows/release.yaml | 5 -- .github/workflows/trivy-docker.yaml | 2 +- .github/workflows/update.yaml | 15 +++- CHANGELOG.md | 9 +++ ci/build/build-vscode.sh | 4 +- ci/build/nfpm.yaml | 4 +- ci/build/update-repo.sh | 5 +- ci/helm-chart/Chart.yaml | 2 +- ci/helm-chart/values.yaml | 2 +- ci/release-image/docker-bake.hcl | 9 ++- docs/MAINTAINING.md | 39 ++++------ docs/helm.md | 74 +++++++++---------- docs/install.md | 12 ++- install.sh | 16 ++-- package.json | 7 +- 18 files changed, 133 insertions(+), 219 deletions(-) delete mode 100644 .github/codecov.yml diff --git a/.github/codecov.yml b/.github/codecov.yml deleted file mode 100644 index c2e23821411d..000000000000 --- a/.github/codecov.yml +++ /dev/null @@ -1,31 +0,0 @@ -codecov: - require_ci_to_pass: yes - allow_coverage_offsets: True - -coverage: - precision: 2 - round: down - range: "40...70" - status: - patch: off - notify: - slack: - default: - url: secret:v1::tXC7VwEIKYjNU8HRgRv2GdKOSCt5UzpykKZb+o1eCDqBgb2PEqwE3A26QUPYMLo4BO2qtrJhFIvwhUvlPwyzDCNGoNiuZfXr0UeZZ0y1TcZu672R/NBNMwEPO/e1Ye0pHxjzKHnuH7HqbjFucox/RBQLtiL3J56SWGE3JtbkC6o= - threshold: 1% - only_pulls: false - branches: - - "main" - -parsers: - gcov: - branch_detection: - conditional: yes - loop: yes - method: no - macro: no - -comment: - layout: "reach,diff,flags,files,footer" - behavior: default - require_changes: no diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 35208c7c6fb3..2394d4bb7f86 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -144,16 +144,11 @@ jobs: test/package-lock.json - run: SKIP_SUBMODULE_DEPS=1 npm ci - run: npm run test:unit - - uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 - if: success() - with: - token: ${{ secrets.CODECOV_TOKEN }} build: name: linux-x64 runs-on: ubuntu-22.04 env: - CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} DISABLE_V8_COMPILE_CACHE: 1 VERSION: 0.0.0 VSCODE_TARGET: linux-x64 diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 96400bf5b385..97a12a83ce9b 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -20,85 +20,15 @@ concurrency: cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: - npm: - runs-on: ubuntu-latest - env: - TAG: ${{ inputs.version || github.ref_name }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - NPM_ENVIRONMENT: "production" - - steps: - - name: Set version to tag without leading v - run: | - echo "VERSION=${TAG#v}" >> $GITHUB_ENV - - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6 - with: - node-version-file: .node-version - - - uses: robinraju/release-downloader@28fc21f50d76778e7023361aa1f863e717d3d56f # v1.13 - with: - repository: "coder/code-server" - tag: ${{ env.TAG }} - fileName: "package.tar.gz" - out-file-path: "release-npm-package" - - - run: tar -xzf release-npm-package/package.tar.gz - - run: | - echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > ~/.npmrc - pushd release - npm publish --tag latest --access public - - aur: - runs-on: ubuntu-latest - timeout-minutes: 10 - env: - GH_TOKEN: ${{ secrets.HOMEBREW_GITHUB_API_TOKEN }} - TAG: ${{ inputs.version || github.ref_name }} - - steps: - - name: Set version to tag without leading v - run: | - echo "VERSION=${TAG#v}" >> $GITHUB_ENV - - - name: Checkout code-server-aur repo - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - with: - repository: "cdrci/code-server-aur" - token: ${{ secrets.HOMEBREW_GITHUB_API_TOKEN }} - ref: "master" - - - name: Configure git - run: | - git config --global user.name cdrci - git config --global user.email opensource@coder.com - - - name: Fetch and reset master - run: | - git remote add upstream https://github.com/coder/code-server-aur.git - git fetch upstream - git reset --hard upstream/master - git push --force - - - name: Validate package - uses: heyhusen/archlinux-package-action@3f7aaada28c782497bfe02d6d6ea365b25fdea12 # v3.0.1 - with: - pkgver: ${{ env.VERSION }} - updpkgsums: true - srcinfo: true - - - name: Open PR - run: | - git checkout -b update-version-${{ env.VERSION }} - git add . - git commit -m "Update to ${{ env.VERSION }}" - git push -u origin $(git branch --show) - gh pr create --repo coder/code-server-aur --title "Update to ${{ env.VERSION }}" --body "PR opened by @$GITHUB_ACTOR" --assignee $GITHUB_ACTOR - + # Publishes the container image to this repository's GitHub Container + # Registry namespace. This is the only artifact other MotusLabs projects + # consume besides the release assets themselves; nothing is pushed outside + # the organization. docker: runs-on: ubuntu-latest + permissions: + contents: read # To download the release assets. + packages: write # To push the image to ghcr.io. env: GITHUB_TOKEN: ${{ github.token }} TAG: ${{ inputs.version || github.ref_name }} @@ -108,29 +38,33 @@ jobs: run: | echo "VERSION=${TAG#v}" >> $GITHUB_ENV + # ghcr.io only accepts lowercase names, while the repository this runs + # in may be spelled with capitals. + - name: Set image name from this repository + run: | + echo "GITHUB_REGISTRY=ghcr.io/$(echo "$GITHUB_REPOSITORY" | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0 - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 - with: - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_PASSWORD }} - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} + # The packages come from this repository's own release, so the image is + # built from the fork's build and not from upstream's. - uses: robinraju/release-downloader@28fc21f50d76778e7023361aa1f863e717d3d56f # v1.13 with: - repository: "coder/code-server" + repository: ${{ github.repository }} tag: v${{ env.VERSION }} fileName: "*.deb" out-file-path: "release-packages" - uses: robinraju/release-downloader@28fc21f50d76778e7023361aa1f863e717d3d56f # v1.13 with: - repository: "coder/code-server" + repository: ${{ github.repository }} tag: v${{ env.VERSION }} fileName: "*.rpm" out-file-path: "release-packages" @@ -139,8 +73,11 @@ jobs: repo: runs-on: ubuntu-latest + permissions: + contents: write # To push the branch. + pull-requests: write # To open the PR. env: - GH_TOKEN: ${{ secrets.HOMEBREW_GITHUB_API_TOKEN }} + GH_TOKEN: ${{ github.token }} TAG: ${{ inputs.version || github.ref_name }} needs: docker @@ -155,13 +92,13 @@ jobs: - name: Open PR run: | - git config --global user.name cdrci - git config --global user.email opensource@coder.com + git config --global user.name "github-actions[bot]" + git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" git checkout -b "helm/$VERSION" git add . git commit -m "Update Helm chart and changelog with $VERSION" git push -u origin "$(git branch --show)" gh pr create \ - --repo coder/code-server \ + --repo "$GITHUB_REPOSITORY" \ --body-file .cache/checklist \ --title "Update Helm chart and changelog with $VERSION" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 569407d581c1..09a996dbea50 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -14,7 +14,6 @@ on: permissions: contents: write # For creating releases. - discussions: write # For creating a discussion. # Cancel in-progress runs for pull requests when developers push # additional changes @@ -114,7 +113,6 @@ jobs: if: ${{ matrix.vscode_arch == 'x64' }} with: draft: true - discussion_category_name: "📣 Announcements" files: package.tar.gz tag_name: v${{ env.VERSION }} name: v${{ env.VERSION }} @@ -126,7 +124,6 @@ jobs: - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 with: draft: true - discussion_category_name: "📣 Announcements" files: ./release-packages/* tag_name: v${{ env.VERSION }} name: v${{ env.VERSION }} @@ -192,7 +189,6 @@ jobs: - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 with: draft: true - discussion_category_name: "📣 Announcements" files: ./release-packages/* tag_name: v${{ env.VERSION }} name: v${{ env.VERSION }} @@ -341,7 +337,6 @@ jobs: - uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2 with: draft: true - discussion_category_name: "📣 Announcements" files: ./release-packages/* tag_name: v${{ env.VERSION }} name: v${{ env.VERSION }} diff --git a/.github/workflows/trivy-docker.yaml b/.github/workflows/trivy-docker.yaml index 7ad57f8dc34f..5b6c30c3dd93 100644 --- a/.github/workflows/trivy-docker.yaml +++ b/.github/workflows/trivy-docker.yaml @@ -51,7 +51,7 @@ jobs: - name: Run Trivy vulnerability scanner in image mode uses: aquasecurity/trivy-action@d2a0b60797ff03db6132bd4e2b293f9b37081297 # latest with: - image-ref: "docker.io/codercom/code-server:latest" + image-ref: "ghcr.io/motuslabs/code-server:latest" ignore-unfixed: true format: "sarif" output: "trivy-image-results.sarif" diff --git a/.github/workflows/update.yaml b/.github/workflows/update.yaml index b54826c79f70..e2d320e6cdcb 100644 --- a/.github/workflows/update.yaml +++ b/.github/workflows/update.yaml @@ -9,12 +9,19 @@ on: schedule: - cron: "0 16,21 * * *" +permissions: + contents: write # To push the update branch. + pull-requests: write # To open the update PR. + jobs: update: runs-on: ubuntu-latest env: TAG: ${{ inputs.version }} - GH_TOKEN: ${{ secrets.HOMEBREW_GITHUB_API_TOKEN }} + # A branch pushed with the built-in token does not start other + # workflows, so the update PR gets no CI. Set UPDATE_PR_TOKEN to an + # organization PAT to get it; without one this still opens the PR. + GH_TOKEN: ${{ secrets.UPDATE_PR_TOKEN || github.token }} steps: - name: Fetch latest tag @@ -59,14 +66,14 @@ jobs: - name: Open PR if: steps.check.outputs.done == 'false' run: | - git config --global user.name cdrci - git config --global user.email opensource@coder.com + git config --global user.name "github-actions[bot]" + git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" git checkout -b "update/$VERSION" git add . git commit -m "Update Code to $VERSION" git push -u origin "$(git branch --show)" gh pr create \ - --repo coder/code-server \ + --repo "$GITHUB_REPOSITORY" \ --title "Update Code to $VERSION" \ --body-file .cache/checklist \ --draft diff --git a/CHANGELOG.md b/CHANGELOG.md index db700a5c7565..cc278c0342e1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -22,6 +22,15 @@ Code v99.99.999 ## Unreleased +### Changed + +- Releases are published inside the organization only. The container image now + goes to `ghcr.io/motuslabs/code-server` instead of Docker Hub and + `ghcr.io/coder/code-server`, and the npm and AUR publishing steps are gone. + `install.sh`, the Docker build and the Helm chart all read from this + repository's releases, so they install this fork's build rather than + upstream's. + ### Fixed - Copying from the terminal with OSC 52 (used by tmux, vim, Claude Code and diff --git a/ci/build/build-vscode.sh b/ci/build/build-vscode.sh index a7db93a1a177..a33cf0b6348f 100755 --- a/ci/build/build-vscode.sh +++ b/ci/build/build-vscode.sh @@ -78,14 +78,14 @@ main() { "applicationName": "code-server", "dataFolderName": ".code-server", "win32MutexName": "codeserver", - "licenseUrl": "https://github.com/coder/code-server/blob/main/LICENSE", + "licenseUrl": "https://github.com/MotusLabs/code-server/blob/main/LICENSE", "win32DirName": "code-server", "win32NameVersion": "code-server", "win32AppUserModelId": "coder.code-server", "win32ShellNameShort": "c&ode-server", "darwinBundleIdentifier": "com.coder.code.server", "linuxIconName": "com.coder.code.server", - "reportIssueUrl": "https://github.com/coder/code-server/issues/new", + "reportIssueUrl": "https://github.com/MotusLabs/code-server/issues/new", "documentationUrl": "https://go.microsoft.com/fwlink/?LinkID=533484#vscode", "keyboardShortcutsUrlMac": "https://go.microsoft.com/fwlink/?linkid=832143", "keyboardShortcutsUrlLinux": "https://go.microsoft.com/fwlink/?linkid=832144", diff --git a/ci/build/nfpm.yaml b/ci/build/nfpm.yaml index 4b0ee371a2eb..1ccdbbcc1bb4 100644 --- a/ci/build/nfpm.yaml +++ b/ci/build/nfpm.yaml @@ -7,8 +7,8 @@ priority: "optional" maintainer: "Joe Previte " description: | Run VS Code in the browser. -vendor: "Coder" -homepage: "https://github.com/coder/code-server" +vendor: "MotusLabs" +homepage: "https://github.com/MotusLabs/code-server" license: "MIT" contents: diff --git a/ci/build/update-repo.sh b/ci/build/update-repo.sh index 0f1924fa91a4..83eb1614c65e 100755 --- a/ci/build/update-repo.sh +++ b/ci/build/update-repo.sh @@ -67,7 +67,7 @@ function update_helm() { function update_changelog() { local date date=$(printf '%(%Y-%m-%d)T\n' -1) - local link="https://github.com/coder/code-server/releases/tag/v$version" + local link="${GITHUB_SERVER_URL:-https://github.com}/${GITHUB_REPOSITORY:-MotusLabs/code-server}/releases/tag/v$version" sed -i.bak "s|## Unreleased|## Unreleased\n\n## [$version]($link) - $date|" CHANGELOG.md } @@ -88,9 +88,6 @@ function main() { # Even if a step failed, still output the last checkmark. run-steps "${steps[@]}" || true - - # This step is always manual. - echo "- [ ] https://github.com/coder/code-server-aur/pulls" >> .cache/checklist } main "$@" diff --git a/ci/helm-chart/Chart.yaml b/ci/helm-chart/Chart.yaml index 3609d3167998..b084c7da111b 100644 --- a/ci/helm-chart/Chart.yaml +++ b/ci/helm-chart/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 name: code-server -description: A Helm chart for coder/code-server +description: A Helm chart for MotusLabs/code-server # A chart can be either an 'application' or a 'library' chart. # diff --git a/ci/helm-chart/values.yaml b/ci/helm-chart/values.yaml index 2f9de03cfa42..e4983a6fe400 100644 --- a/ci/helm-chart/values.yaml +++ b/ci/helm-chart/values.yaml @@ -5,7 +5,7 @@ replicaCount: 1 image: - repository: codercom/code-server + repository: ghcr.io/motuslabs/code-server tag: '4.137.0' pullPolicy: Always diff --git a/ci/release-image/docker-bake.hcl b/ci/release-image/docker-bake.hcl index ecb0c313daed..78a98b3f30ed 100644 --- a/ci/release-image/docker-bake.hcl +++ b/ci/release-image/docker-bake.hcl @@ -6,12 +6,17 @@ variable "VERSION" { default = "latest" } +# Publishing happens inside the organization only. Docker Hub is disabled by +# leaving this empty; gen_tags then generates no tags for it. Set it only if +# the organization ever runs its own registry. variable "DOCKER_REGISTRY" { - default = "docker.io/codercom/code-server" + default = "" } +# Overridden by the publish workflow with the ghcr.io namespace of whichever +# repository is running it. variable "GITHUB_REGISTRY" { - default = "ghcr.io/coder/code-server" + default = "ghcr.io/motuslabs/code-server" } group "default" { diff --git a/docs/MAINTAINING.md b/docs/MAINTAINING.md index 69263576ec2c..82643ba71176 100644 --- a/docs/MAINTAINING.md +++ b/docs/MAINTAINING.md @@ -5,10 +5,8 @@ - [Releasing](#releasing) - [Release Candidates](#release-candidates) - - [AUR](#aur) + - [Release assets](#release-assets) - [Docker](#docker) - - [nixpkgs](#nixpkgs) - - [npm](#npm) - [Testing](#testing) - [Documentation](#documentation) - [Troubleshooting](#troubleshooting) @@ -37,7 +35,6 @@ Most of the work is keeping on top of issues and discussions. 6. Publish the draft release after validating it. 7. Update the changelog with the release date and bump the Helm chart version once the Docker images have published. -8. Merge the PR submitted to coder/code-server-aur repo. #### Release Candidates @@ -50,31 +47,27 @@ full-blown release. To do this follow the same steps as above but: 3. Do not update the chart version or merge in the changelog until the final release. -#### AUR +#### Release assets -We publish to AUR as a package -[here](https://aur.archlinux.org/packages/code-server/). This process is manual -and can be done by following the steps in [this -repo](https://github.com/coder/code-server-aur). +Every release carries the platform-agnostic `package.tar.gz` plus the +platform-specific `.deb`, `.rpm` and standalone tarballs, attached to the +release in this repository. `install.sh` pulls from here, so it installs this +fork's build and not upstream's. #### Docker -We publish code-server as a Docker image -[here](https://hub.docker.com/r/codercom/code-server), tagging it both with the -version and latest. +We publish code-server as a Docker image to this repository's GitHub Container +Registry namespace, `ghcr.io/motuslabs/code-server`, tagging it both with the +version and latest. This is automated with the release process and runs off the +`.deb` and `.rpm` from the release above. -This is currently automated with the release process. +Consumers need a GitHub login with read access to the organization's packages, +or the package has to be made visible to the organization in its package +settings. -#### nixpkgs - -We publish code-server in nixpkgs but it must be updated manually. - -#### npm - -We publish code-server as a npm package -[here](https://www.npmjs.com/package/code-server/v/latest). - -This is currently automated with the release process. +This fork does not publish to npm, Docker Hub, the AUR, Homebrew or nixpkgs. +Nothing in CI should push outside the organization; if a build needs to be +shared elsewhere, that is a decision to make deliberately rather than a default. ## Testing diff --git a/docs/helm.md b/docs/helm.md index 864a1940cbf4..78ab30af24af 100644 --- a/docs/helm.md +++ b/docs/helm.md @@ -59,43 +59,43 @@ and their default values. ## Values -| Key | Type | Default | -| ------------------------------------------- | ------ | ------------------------ | -| affinity | object | `{}` | -| extraArgs | list | `[]` | -| extraConfigmapMounts | list | `[]` | -| extraContainers | string | `""` | -| extraInitContainers | string | `""` | -| extraSecretMounts | list | `[]` | -| extraVars | list | `[]` | -| extraVolumeMounts | list | `[]` | -| fullnameOverride | string | `""` | -| hostnameOverride | string | `""` | -| image.pullPolicy | string | `"Always"` | -| image.repository | string | `"codercom/code-server"` | -| image.tag | string | `"4.8.0"` | -| imagePullSecrets | list | `[]` | -| ingress.enabled | bool | `false` | -| nameOverride | string | `""` | -| nodeSelector | object | `{}` | -| persistence.accessMode | string | `"ReadWriteOnce"` | -| persistence.annotations | object | `{}` | -| persistence.enabled | bool | `true` | -| persistence.size | string | `"1Gi"` | -| podAnnotations | object | `{}` | -| podSecurityContext | object | `{}` | -| replicaCount | int | `1` | -| resources | object | `{}` | -| securityContext.enabled | bool | `true` | -| securityContext.fsGroup | int | `1000` | -| securityContext.runAsUser | int | `1000` | -| service.port | int | `8443` | -| service.type | string | `"ClusterIP"` | -| serviceAccount.create | bool | `true` | -| serviceAccount.name | string | `nil` | -| tolerations | list | `[]` | -| volumePermissions.enabled | bool | `true` | -| volumePermissions.securityContext.runAsUser | int | `0` | +| Key | Type | Default | +| ------------------------------------------- | ------ | --------------------------------- | +| affinity | object | `{}` | +| extraArgs | list | `[]` | +| extraConfigmapMounts | list | `[]` | +| extraContainers | string | `""` | +| extraInitContainers | string | `""` | +| extraSecretMounts | list | `[]` | +| extraVars | list | `[]` | +| extraVolumeMounts | list | `[]` | +| fullnameOverride | string | `""` | +| hostnameOverride | string | `""` | +| image.pullPolicy | string | `"Always"` | +| image.repository | string | `"ghcr.io/motuslabs/code-server"` | +| image.tag | string | `"4.8.0"` | +| imagePullSecrets | list | `[]` | +| ingress.enabled | bool | `false` | +| nameOverride | string | `""` | +| nodeSelector | object | `{}` | +| persistence.accessMode | string | `"ReadWriteOnce"` | +| persistence.annotations | object | `{}` | +| persistence.enabled | bool | `true` | +| persistence.size | string | `"1Gi"` | +| podAnnotations | object | `{}` | +| podSecurityContext | object | `{}` | +| replicaCount | int | `1` | +| resources | object | `{}` | +| securityContext.enabled | bool | `true` | +| securityContext.fsGroup | int | `1000` | +| securityContext.runAsUser | int | `1000` | +| service.port | int | `8443` | +| service.type | string | `"ClusterIP"` | +| serviceAccount.create | bool | `true` | +| serviceAccount.name | string | `nil` | +| tolerations | list | `[]` | +| volumePermissions.enabled | bool | `true` | +| volumePermissions.securityContext.runAsUser | int | `0` | Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example, diff --git a/docs/install.md b/docs/install.md index edd256ba3072..d2112b5548af 100644 --- a/docs/install.md +++ b/docs/install.md @@ -281,12 +281,16 @@ docker run -it --name code-server -p 127.0.0.1:8080:8080 \ -v "$PWD:/home/coder/project" \ -u "$(id -u):$(id -g)" \ -e "DOCKER_USER=$USER" \ - codercom/code-server:latest + ghcr.io/motuslabs/code-server:latest ``` -Our official image supports `amd64` and `arm64`. For `arm32` support, you can -use a [community-maintained code-server -alternative](https://hub.docker.com/r/linuxserver/code-server). +The image supports `amd64` and `arm64`. It is published to this repository's +GitHub Container Registry namespace, so pulling it needs a GitHub login with +read access to the organization's packages: + +```console +echo "$GITHUB_TOKEN" | docker login ghcr.io -u "$GITHUB_USER" --password-stdin +``` ## Helm diff --git a/install.sh b/install.sh index 28580a871b53..231249f7bf10 100755 --- a/install.sh +++ b/install.sh @@ -75,12 +75,12 @@ EOF echo_latest_version() { if [ "${EDGE-}" ]; then - version="$(curl -fsSL https://api.github.com/repos/coder/code-server/releases | awk 'match($0,/.*"html_url": "(.*\/releases\/tag\/.*)".*/)' | head -n 1 | awk -F '"' '{print $4}')" + version="$(curl -fsSL "https://api.github.com/repos/$REPO/releases" | awk 'match($0,/.*"html_url": "(.*\/releases\/tag\/.*)".*/)' | head -n 1 | awk -F '"' '{print $4}')" else # https://gist.github.com/lukechilds/a83e1d7127b78fef38c2914c4ececc3c#gistcomment-2758860 - version="$(curl -fsSLI -o /dev/null -w "%{url_effective}" https://github.com/coder/code-server/releases/latest)" + version="$(curl -fsSLI -o /dev/null -w "%{url_effective}" "https://github.com/$REPO/releases/latest")" fi - version="${version#https://github.com/coder/code-server/releases/tag/}" + version="${version#https://github.com/"$REPO"/releases/tag/}" version="${version#v}" echo "$version" } @@ -136,6 +136,10 @@ echo_coder_postinstall() { echoh "Deploy code-server for your team with Coder: https://github.com/coder/coder" } +# The repository the release assets are pulled from. This fork carries patches +# that upstream does not have, so the default has to be the fork. +REPO=${REPO:-MotusLabs/code-server} + main() { if [ "${TRACE-}" ]; then set -x @@ -359,7 +363,7 @@ install_deb() { echoh "Installing v$VERSION of the $ARCH deb package from GitHub." echoh - fetch "https://github.com/coder/code-server/releases/download/v$VERSION/code-server_${VERSION}_$ARCH.deb" \ + fetch "https://github.com/$REPO/releases/download/v$VERSION/code-server_${VERSION}_$ARCH.deb" \ "$CACHE_DIR/code-server_${VERSION}_$ARCH.deb" sudo_sh_c dpkg -i "$CACHE_DIR/code-server_${VERSION}_$ARCH.deb" @@ -370,7 +374,7 @@ install_rpm() { echoh "Installing v$VERSION of the $ARCH rpm package from GitHub." echoh - fetch "https://github.com/coder/code-server/releases/download/v$VERSION/code-server-$VERSION-$ARCH.rpm" \ + fetch "https://github.com/$REPO/releases/download/v$VERSION/code-server-$VERSION-$ARCH.rpm" \ "$CACHE_DIR/code-server-$VERSION-$ARCH.rpm" sudo_sh_c rpm -U "$CACHE_DIR/code-server-$VERSION-$ARCH.rpm" @@ -396,7 +400,7 @@ install_standalone() { echoh "Installing v$VERSION of the $ARCH release from GitHub." echoh - fetch "https://github.com/coder/code-server/releases/download/v$VERSION/code-server-$VERSION-$OS-$ARCH.tar.gz" \ + fetch "https://github.com/$REPO/releases/download/v$VERSION/code-server-$VERSION-$OS-$ARCH.tar.gz" \ "$CACHE_DIR/code-server-$VERSION-$OS-$ARCH.tar.gz" # -w only works if the directory exists so try creating it first. If this diff --git a/package.json b/package.json index 1f9ea92c1d3a..2ab2d7b29910 100644 --- a/package.json +++ b/package.json @@ -3,11 +3,11 @@ "license": "MIT", "version": "0.0.0", "description": "Run VS Code on a remote server.", - "homepage": "https://github.com/coder/code-server", + "homepage": "https://github.com/MotusLabs/code-server", "bugs": { - "url": "https://github.com/coder/code-server/issues" + "url": "https://github.com/MotusLabs/code-server/issues" }, - "repository": "https://github.com/coder/code-server", + "repository": "https://github.com/MotusLabs/code-server", "scripts": { "clean": "./ci/build/clean.sh", "build": "./ci/build/build-code-server.sh", @@ -25,7 +25,6 @@ "prettier": "prettier --write --log-level=warn --cache .", "preinstall": "node ./ci/dev/preinstall.js", "postinstall": "./ci/dev/postinstall.sh", - "publish:npm": "./ci/steps/publish-npm.sh", "publish:docker": "./ci/steps/docker-buildx-push.sh", "fmt": "npm run prettier && ./ci/dev/doctoc.sh", "lint:scripts": "./ci/dev/lint-scripts.sh", From 03e2ed9ad9b916dbb58f29d84cf881e6acd32f63 Mon Sep 17 00:00:00 2001 From: ru-sh Date: Fri, 18 Sep 2026 10:34:14 +0400 Subject: [PATCH 2/2] Fail clearly when the repository has no releases With nothing published yet, the latest URL redirects to the releases index rather than a tag, so the prefix strip left the version as a URL and the installer built a download URL out of it, ending in a 404 nobody could read. Upstream never hit this because it always has a release to find. --- install.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/install.sh b/install.sh index 231249f7bf10..66ce576ac1f2 100755 --- a/install.sh +++ b/install.sh @@ -81,6 +81,16 @@ echo_latest_version() { version="$(curl -fsSLI -o /dev/null -w "%{url_effective}" "https://github.com/$REPO/releases/latest")" fi version="${version#https://github.com/"$REPO"/releases/tag/}" + # With nothing published yet the latest URL redirects to the releases index + # instead of a tag, so the prefix above does not strip and the version would + # be a URL. Say so rather than building a download URL out of it. + case $version in + *://*) + echoerr "No releases found at https://github.com/$REPO/releases" + echoerr "Pass --version to install a specific version." + exit 1 + ;; + esac version="${version#v}" echo "$version" }