MrMasterbay 4a702cd742 security: fix web-push IPv6 SSRF bypass + persist-credentials on CI checkouts (Aikido)
- push.py _is_internal_or_metadata_host (#469089273): stopped splitting the host on
  ':' (which mangled every IPv6 literal, '::1' -> '', bypassing the block) and unwrap
  IPv4-mapped IPv6 (::ffff:a.b.c.d) so metadata/private checks apply. +6 unit tests.
- docker.yml + release-images.yml (#348463387/#348463388): persist-credentials:false on
  the actions/checkout steps that never push.
2026-08-10 08:36:27 +02:00

78 lines
3.3 KiB
YAML

name: Build Docker Image
# MK: builds multi-arch image and pushes to ghcr.io
# NS 2026-06-05 — only build on a released version tag (v*), NOT on every main
# push. main moves constantly and we don't want a Docker image per commit; the
# v* tag is pushed when a release is cut. workflow_dispatch stays as the manual
# escape hatch (a dispatch from main still refreshes :latest via is_default_branch).
on:
push:
tags: ['v*']
workflow_dispatch:
# MK May 2026 — top-level permissions implicitly cascaded `packages: write`
# into any future job added to this workflow. Aikido flagged it as overly
# broad. Scope per-job instead so only build-and-push gets the GHCR write.
permissions:
contents: read
jobs:
build-and-push:
runs-on: ubuntu-latest
# MK May 2026 — minimum perms for the build:
# contents: read → actions/checkout@v4
# packages: write → docker/login-action@v3 + push to ghcr.io
# MK 2026-06-10 — dropped the gha layer cache (no-cache below) so every
# release rebuilds clean and `apt upgrade -y` always pulls the latest Debian
# security patches; the old cache had frozen a stale openssl into the image.
# That also makes the previous actions:write perm (cache export) unnecessary.
permissions:
contents: read
packages: write
steps:
# NS 2026-05-30 — third-party actions pinned to commit SHA so a re-tag of
# the moving v4/v3/v5 reference (e.g. action repo compromise) can't smuggle
# malicious code into the release build. Comments after the SHA are the
# human-readable tag we resolved from at pin time; dependabot/renovate can
# bump these via PR.
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- name: Set up QEMU
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
- name: Set up Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Image metadata
id: meta
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
with:
images: ghcr.io/pegaprox/pegaprox
tags: |
type=match,pattern=v(.*),group=1
type=raw,value=latest,enable={{is_default_branch}}
type=raw,value=latest,enable=${{ startsWith(github.ref, 'refs/tags/v') }}
- name: Build and push
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
# MK 2026-06-10 — no cache: force a fresh build each release so the apt
# security upgrade re-runs and the published image never ships a stale
# openssl/libssl3 (Aikido CVE-2026-45447/7383 et al). Build is
# tag-triggered, so the full-rebuild cost is fine.
no-cache: true