mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
- push.py _is_internal_or_metadata_host (#469089273): stopped splitting the host on ':' (which mangled every IPv6 literal, '::1' -> '', bypassing the block) and unwrap IPv4-mapped IPv6 (::ffff:a.b.c.d) so metadata/private checks apply. +6 unit tests. - docker.yml + release-images.yml (#348463387/#348463388): persist-credentials:false on the actions/checkout steps that never push.
78 lines
3.3 KiB
YAML
78 lines
3.3 KiB
YAML
name: Build Docker Image
|
|
|
|
# MK: builds multi-arch image and pushes to ghcr.io
|
|
# NS 2026-06-05 — only build on a released version tag (v*), NOT on every main
|
|
# push. main moves constantly and we don't want a Docker image per commit; the
|
|
# v* tag is pushed when a release is cut. workflow_dispatch stays as the manual
|
|
# escape hatch (a dispatch from main still refreshes :latest via is_default_branch).
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
|
|
# MK May 2026 — top-level permissions implicitly cascaded `packages: write`
|
|
# into any future job added to this workflow. Aikido flagged it as overly
|
|
# broad. Scope per-job instead so only build-and-push gets the GHCR write.
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-and-push:
|
|
runs-on: ubuntu-latest
|
|
# MK May 2026 — minimum perms for the build:
|
|
# contents: read → actions/checkout@v4
|
|
# packages: write → docker/login-action@v3 + push to ghcr.io
|
|
# MK 2026-06-10 — dropped the gha layer cache (no-cache below) so every
|
|
# release rebuilds clean and `apt upgrade -y` always pulls the latest Debian
|
|
# security patches; the old cache had frozen a stale openssl into the image.
|
|
# That also makes the previous actions:write perm (cache export) unnecessary.
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
steps:
|
|
# NS 2026-05-30 — third-party actions pinned to commit SHA so a re-tag of
|
|
# the moving v4/v3/v5 reference (e.g. action repo compromise) can't smuggle
|
|
# malicious code into the release build. Comments after the SHA are the
|
|
# human-readable tag we resolved from at pin time; dependabot/renovate can
|
|
# bump these via PR.
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
|
|
|
|
- name: Set up Buildx
|
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Image metadata
|
|
id: meta
|
|
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
|
|
with:
|
|
images: ghcr.io/pegaprox/pegaprox
|
|
tags: |
|
|
type=match,pattern=v(.*),group=1
|
|
type=raw,value=latest,enable={{is_default_branch}}
|
|
type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') }}
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0
|
|
with:
|
|
context: .
|
|
platforms: linux/amd64,linux/arm64
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
# MK 2026-06-10 — no cache: force a fresh build each release so the apt
|
|
# security upgrade re-runs and the published image never ships a stale
|
|
# openssl/libssl3 (Aikido CVE-2026-45447/7383 et al). Build is
|
|
# tag-triggered, so the full-rebuild cost is fine.
|
|
no-cache: true
|