mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
Two non-blocking findings from the Aikido + CodeAnt daily scan on the new docker-testing.yml: - checkout persisted GITHUB_TOKEN into .git/config (Aikido, med). This job never pushes git, so set persist-credentials: false — a compromised downstream action can no longer lift the token from the checkout. - workflow_dispatch could be fired from any branch and publish it as pegaprox-testing:latest (CodeAnt). Guard the job on refs/heads/Testing so a dispatch from elsewhere is a harmless no-op.
73 lines
2.8 KiB
YAML
73 lines
2.8 KiB
YAML
name: Build Testing Docker Image
|
|
|
|
# NS Aug 2026 — on every push to Testing, publish a dev image to its OWN package
|
|
# ghcr.io/pegaprox/pegaprox-testing so people can track the dev branch via
|
|
# docker pull ghcr.io/pegaprox/pegaprox-testing:latest
|
|
# Kept fully separate from docker.yml (release-tag-only) so it never touches the
|
|
# release build. amd64-only + no-cache: a Testing push is frequent, but each build
|
|
# stays clean (same posture as the release image) so `apt upgrade` re-pulls the
|
|
# current Debian security patches instead of freezing a stale openssl into the image.
|
|
# The Dockerfile COPYs the committed web/index.html — so run web/Dev/build.sh and
|
|
# commit the UI before pushing, as usual.
|
|
# NOTE: the pegaprox-testing GHCR package is created PRIVATE on the first run —
|
|
# flip it to public once in the package settings.
|
|
on:
|
|
push:
|
|
branches: [Testing]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
# rapid Testing pushes: cancel a superseded build instead of queuing N of them
|
|
concurrency:
|
|
group: docker-testing-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
build-and-push:
|
|
# MK 2026-08-09 (Aikido/CodeAnt daily scan) — a workflow_dispatch can be fired from ANY
|
|
# branch; without this guard that would publish an arbitrary branch as pegaprox-testing:latest.
|
|
# Pin the job to the Testing ref so a dispatch from elsewhere is a harmless no-op.
|
|
if: github.ref == 'refs/heads/Testing'
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
steps:
|
|
# third-party actions pinned to the same commit SHAs as docker.yml
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
|
|
# MK 2026-08-09 — don't persist GITHUB_TOKEN into .git/config; this job never pushes
|
|
# git, so a compromised downstream action can't lift the token from the checkout.
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Set up Buildx
|
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
|
|
|
|
- name: Log in to GHCR
|
|
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Image metadata
|
|
id: meta
|
|
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5.10.0
|
|
with:
|
|
images: ghcr.io/pegaprox/pegaprox-testing
|
|
tags: |
|
|
type=raw,value=latest
|
|
type=sha,format=short
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@ca052bb54ab0790a636c9b5f226502c73d547a25 # v5.4.0
|
|
with:
|
|
context: .
|
|
platforms: linux/amd64
|
|
push: true
|
|
tags: ${{ steps.meta.outputs.tags }}
|
|
labels: ${{ steps.meta.outputs.labels }}
|
|
no-cache: true
|