Repository navigation
Say what Glama actually builds, which is not our Dockerfile - #107
Merged
Merged
Conversation
The previous commit added a Dockerfile and justified it with a claim that is wrong. Glama's methodology says a server is built "from a Dockerfile ... authored by the maintainer and checked into the repository, or inferred by Glama's AI-assisted build system", and I read the first branch as ours. It is not. The server's admin page is a form - base image, build steps, CMD, environment schema - Glama generates its own Dockerfile from those fields, clones this repository into `/app` at a pinned commit, and runs the build steps there. Nothing reads the file at the root. That was discoverable before writing it, and the cost of not discovering it is a README that teaches a stranger something untrue about how their listing gets built. So the paragraph goes, and the file keeps only the reasons that survive contact with the facts: CI builds it on every pull request and speaks a real handshake to the result, which is the only check here that exercises the published package rather than the source tree, and it is still the shortest way for somebody to watch this server run without installing anything of ours. `docs/glama-build-spec.md` is the part that was missing. The fields Glama does read live on their website, where nothing in this repository can check them, so the next best thing is to keep the document somebody copies them from. It records what their inference produced and why all three parts of it fail here: `pnpm` against a repository with a `package-lock.json`, a `run build` that wants Electron to produce bundles this server does not start from, and a `bin/gitwarren.mjs` that exists only inside the published package. What replaces it installs that published package and runs it, which is the artifact every agent actually starts and therefore the honest thing to put in front of a scanner. The version in that document is pinned, so `sync-plugin-versions.mjs` now covers it too, matching only the pinned spellings so the prose can go on saying `npx gitwarren mcp` untouched. It cannot reach the field on Glama's website and does not pretend to; what it keeps current is the line somebody copies. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The previous change added a Dockerfile and justified it with a claim that is
wrong. Glama does not build it.
Their methodology says a server is built "from a Dockerfile … authored by the
maintainer and checked into the repository, or inferred by Glama's AI-assisted
build system", and I read the first branch as ours. It is not. The server's
admin page is a form, and Glama generates its own Dockerfile from those fields,
clones this repository into
/appat a pinned commit, and runs the build stepsthere. The generated file confirms it. Nothing in it references what is
committed at the root. Another maintainer hit this and removed theirs.
So this removes the false paragraph, keeps the Dockerfile for the reasons that
actually hold, and writes down the fields Glama does read.
What the Dockerfile is still worth
Two things, both smaller than the reason it was written for:
That is the only check in this repository that exercises the published
package rather than the source tree.
installing anything of ours.
The new document
docs/glama-build-spec.mdrecords the fields to paste into the admin page andwhy. Glama's inference for this repository produces:
All three parts fail here.
pnpmagainst a repository with apackage-lock.jsonand no pnpm lockfile.run buildtypechecks and runs fourVite builds, needing the Electron dependency and its platform binary download,
to produce bundles this server does not start from. And
bin/gitwarren.mjsdoes not exist in this repository at all: that launcher is
packaging/npm/bin/gitwarren.mjs, published rather than checked out, loading abundle that exists only inside the built package.
What replaces it installs the published package and runs that, which is the
artifact every agent starts and therefore the honest thing to put in front of
a scanner.
Verified against a copy of their image
Their generated Dockerfile was reproduced verbatim down to the base image, the
NodeSource install, the clone and the
PATH, with only the build step and CMDswapped for the recommended ones, and built for x86-64.
npm install -g gitwarren@0.1.17cc,gcc,g++andmakeare all absentbetter-sqlite3bindinglinux-x64.node, shipped in the package/tmp/gitwarren/gitwarren.db, where the placeholder puts itmcp-proxyThe absent toolchain is the interesting row. It means the recommended build
step needs nothing beyond what their base image already provides, so it cannot
fail for want of a compiler on their infrastructure.
Version drift
The document pins a version, so
sync-plugin-versions.mjsnow covers it,matching only pinned spellings so the surrounding prose can go on saying
npx gitwarren mcpuntouched. It cannot reach the field on Glama's website and thedocument says so. What it keeps current is the line somebody copies.
🤖 Generated with Claude Code