name: Build Testing Docker Image # NS Aug 2026 — on every push to Testing, publish a dev image to its OWN package # ghcr.io/pegaprox/pegaprox-testing so people can track the dev branch via # docker pull ghcr.io/pegaprox/pegaprox-testing:latest # Kept fully separate from docker.yml (release-tag-only) so it never touches the # release build. amd64-only + no-cache: a Testing push is frequent, but each build # stays clean (same posture as the release image) so `apt upgrade` re-pulls the # current Debian security patches instead of freezing a stale openssl into the image. # The Dockerfile COPYs the committed web/index.html — so run web/Dev/build.sh and # commit the UI before pushing, as usual. # NOTE: the pegaprox-testing GHCR package is created PRIVATE on the first run — # flip it to public once in the package settings. on: push: branches: [Testing] workflow_dispatch: permissions: contents: read # rapid Testing pushes: cancel a superseded build instead of queuing N of them concurrency: group: docker-testing-${{ github.ref }} cancel-in-progress: true jobs: build-and-push: # MK 2026-08-09 (Aikido/CodeAnt daily scan) — a workflow_dispatch can be fired from ANY # branch; without this guard that would publish an arbitrary branch as pegaprox-testing:latest. # Pin the job to the Testing ref so a dispatch from elsewhere is a harmless no-op. if: github.ref == 'refs/heads/Testing' runs-on: ubuntu-latest permissions: contents: read packages: write steps: # third-party actions pinned to the same commit SHAs as docker.yml - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 # MK 2026-08-09 — don't persist GITHUB_TOKEN into .git/config; this job never pushes # git, so a compromised downstream action can't lift the token from the checkout. with: persist-credentials: false - name: Set up Buildx uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0 - name: Log in to GHCR uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Image metadata id: meta uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0 with: images: ghcr.io/pegaprox/pegaprox-testing tags: | type=raw,value=latest type=sha,format=short - name: Build and push uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0 with: context: . platforms: linux/amd64 push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} no-cache: true