mkellermann97 c995284124 ci(docker): harden the Testing docker workflow (daily security scan)
Two non-blocking findings from the Aikido + CodeAnt daily scan on the new
docker-testing.yml:
- checkout persisted GITHUB_TOKEN into .git/config (Aikido, med). This job never
  pushes git, so set persist-credentials: false — a compromised downstream action
  can no longer lift the token from the checkout.
- workflow_dispatch could be fired from any branch and publish it as
  pegaprox-testing:latest (CodeAnt). Guard the job on refs/heads/Testing so a
  dispatch from elsewhere is a harmless no-op.
2026-08-09 08:46:02 +02:00

73 lines
2.8 KiB
YAML

name: Build Testing Docker Image
# NS Aug 2026 — on every push to Testing, publish a dev image to its OWN package
# ghcr.io/pegaprox/pegaprox-testing so people can track the dev branch via
# docker pull ghcr.io/pegaprox/pegaprox-testing:latest
# Kept fully separate from docker.yml (release-tag-only) so it never touches the
# release build. amd64-only + no-cache: a Testing push is frequent, but each build
# stays clean (same posture as the release image) so `apt upgrade` re-pulls the
# current Debian security patches instead of freezing a stale openssl into the image.
# The Dockerfile COPYs the committed web/index.html — so run web/Dev/build.sh and
# commit the UI before pushing, as usual.
# NOTE: the pegaprox-testing GHCR package is created PRIVATE on the first run —
# flip it to public once in the package settings.
on:
push:
branches: [Testing]
workflow_dispatch:
permissions:
contents: read
# rapid Testing pushes: cancel a superseded build instead of queuing N of them
concurrency:
group: docker-testing-${{ github.ref }}
cancel-in-progress: true
jobs:
build-and-push:
# MK 2026-08-09 (Aikido/CodeAnt daily scan) — a workflow_dispatch can be fired from ANY
# branch; without this guard that would publish an arbitrary branch as pegaprox-testing:latest.
# Pin the job to the Testing ref so a dispatch from elsewhere is a harmless no-op.
if: github.ref == 'refs/heads/Testing'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
# third-party actions pinned to the same commit SHAs as docker.yml
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
# MK 2026-08-09 — don't persist GITHUB_TOKEN into .git/config; this job never pushes
# git, so a compromised downstream action can't lift the token from the checkout.
with:
persist-credentials: false
- name: Set up Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Image metadata
id: meta
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
with:
images: ghcr.io/pegaprox/pegaprox-testing
tags: |
type=raw,value=latest
type=sha,format=short
- name: Build and push
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0
with:
context: .
platforms: linux/amd64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
no-cache: true