← Pipelines

Image pinning

Every image in a gittan pipeline has a digest. No exceptions.

Why :latest is banned

A container tag is a mutable pointer. node:22-slim today and node:22-slim tomorrow are not the same image. If your pipeline passes on Monday and fails on Tuesday with no code change, the image changed under you. This is not a theoretical risk — it happens constantly.

The :latest tag is worse: it is a moving target that can jump major versions. gittan refuses it outright.

Two tiers of images

TierHow it works
Vettedgittan/node:22 — maintained by the platform. Pinned to a specific digest internally. You write the short name, the resolver maps it to an immutable image.
UserAny image from the org registry or a public registry. Must include a digest: myimage@sha256:abc.... Untagged or :latest images are rejected.

What this prevents

  • Non-reproducible builds (same code, different result)
  • Supply chain attacks via tag poisoning
  • Silent base image changes breaking production
  • Debugging sessions caused by upstream image drift

Image allowlist

Org admins can configure which external images are allowed in pipelines. The gittan vetted images are always available. Everything else requires explicit approval — no marketplace, no third-party Actions, no unvetted dependencies in the build pipeline.