Two non-blocking findings from the Aikido + CodeAnt daily scan on the new
docker-testing.yml:
- checkout persisted GITHUB_TOKEN into .git/config (Aikido, med). This job never
pushes git, so set persist-credentials: false — a compromised downstream action
can no longer lift the token from the checkout.
- workflow_dispatch could be fired from any branch and publish it as
pegaprox-testing:latest (CodeAnt). Guard the job on refs/heads/Testing so a
dispatch from elsewhere is a harmless no-op.
New workflow, kept separate from the release-tag-only docker.yml so it never
touches the release build. On every push to Testing it builds the Dockerfile and
publishes to its own package ghcr.io/pegaprox/pegaprox-testing (:latest + a
:sha-<short> immutable tag). amd64-only + no-cache (clean build each time so the
apt security upgrade re-runs), concurrency cancels superseded builds.
The pegaprox-testing GHCR package is created private on the first run — flip it to
public once in the package settings.