2 Commits

Author SHA1 Message Date
mkellermann97
c995284124 ci(docker): harden the Testing docker workflow (daily security scan)
Two non-blocking findings from the Aikido + CodeAnt daily scan on the new
docker-testing.yml:
- checkout persisted GITHUB_TOKEN into .git/config (Aikido, med). This job never
  pushes git, so set persist-credentials: false — a compromised downstream action
  can no longer lift the token from the checkout.
- workflow_dispatch could be fired from any branch and publish it as
  pegaprox-testing:latest (CodeAnt). Guard the job on refs/heads/Testing so a
  dispatch from elsewhere is a harmless no-op.
2026-08-09 08:46:02 +02:00
MrMasterbay
df09fe22a6 ci(docker): build a dev image on every Testing push
New workflow, kept separate from the release-tag-only docker.yml so it never
touches the release build. On every push to Testing it builds the Dockerfile and
publishes to its own package ghcr.io/pegaprox/pegaprox-testing (:latest + a
:sha-<short> immutable tag). amd64-only + no-cache (clean build each time so the
apt security upgrade re-runs), concurrency cancels superseded builds.

The pegaprox-testing GHCR package is created private on the first run — flip it to
public once in the package settings.
2026-08-08 19:42:40 +02:00