# The image the `pwsh` job of ci.yml runs in: Debian, PowerShell 7 and PSScriptAnalyzer,
# plus what the tool preflight and the suite need (Gitea #151, D37). Built by
# `.gitea/workflows/pwsh-ci-image.yml`, never by hand.
FROM debian:trixie-slim

ARG PWSH_VERSION

# `nodejs` is for act_runner, which executes JavaScript actions (checkout) inside the job
# container. `libicu76` is what PowerShell's .NET needs for culture data; `iconv` converts
# the UTF-16 checksum list the PowerShell release publishes.
RUN set -eu; \
    test -n "$PWSH_VERSION"; \
    apt-get update -qq; \
    apt-get install -y --no-install-recommends \
      ca-certificates curl git nodejs python3 python3-venv ripgrep libicu76; \
    base="https://github.com/PowerShell/PowerShell/releases/download/v${PWSH_VERSION}"; \
    tarball="powershell-${PWSH_VERSION}-linux-x64.tar.gz"; \
    curl -fsSL -o "/tmp/${tarball}" "${base}/${tarball}"; \
    curl -fsSL "${base}/hashes.sha256" | iconv -f UTF-16 -t UTF-8 | tr -d '\r' > /tmp/hashes.sha256; \
    expected="$(grep -F "*${tarball}" /tmp/hashes.sha256 | cut -d' ' -f1)"; \
    test -n "$expected"; \
    echo "${expected}  /tmp/${tarball}" | sha256sum -c -; \
    mkdir -p /opt/microsoft/powershell/7; \
    tar -xzf "/tmp/${tarball}" -C /opt/microsoft/powershell/7; \
    chmod +x /opt/microsoft/powershell/7/pwsh; \
    ln -s /opt/microsoft/powershell/7/pwsh /usr/local/bin/pwsh; \
    rm -rf /tmp/* /var/lib/apt/lists/*

RUN pwsh -NoProfile -Command \
      "Set-PSRepository PSGallery -InstallationPolicy Trusted; Install-Module PSScriptAnalyzer -Scope AllUsers -Force"

LABEL org.opencontainers.image.title="chemenu-ci-pwsh" \
      org.opencontainers.image.description="PowerShell 7 and PSScriptAnalyzer for chemenu's pwsh CI job" \
      chemenu.pwsh-version="${PWSH_VERSION}"
