Skip to content

chore(deps): update docker/setup-buildx-action action to v4.4.1 #160

chore(deps): update docker/setup-buildx-action action to v4.4.1

chore(deps): update docker/setup-buildx-action action to v4.4.1 #160

Workflow file for this run

name: Build/Publish Docker Image
permissions: read-all
on:
release:
types:
- published
push:
branches:
- main
tags:
- v*
paths-ignore:
- "docs/**"
- "**/*.md"
pull_request:
paths-ignore:
- "docs/**"
- "**/*.md"
types: [labeled, unlabeled, opened, synchronize, reopened]
jobs:
buildAndPush:
strategy:
matrix:
image:
- name: quota-controller
target: controller
- name: quota-webhook
target: webhook
permissions:
contents: read
packages: write
id-token: write
attestations: write
name: Build and Publish Docker Image
if: |
github.event_name == 'push' ||
(github.event_name == 'pull_request' && contains(github.event.pull_request.labels.*.name, 'ok-to-image')) ||
(github.event_name == 'release' && github.event.action == 'published')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
id: meta
with:
images: |
ghcr.io/${{ github.repository_owner }}/${{ matrix.image.name }}
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=ref,event=branch
type=ref,event=tag
type=ref,event=pr
type=sha
flavor: |
latest=${{ github.ref == 'refs/heads/main' }}
- name: Set up QEMU
uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0
with:
platforms: arm64
- name: Set up Docker Buildx
timeout-minutes: 5
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Login to GHCR
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
id: image
timeout-minutes: 20
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
target: ${{ matrix.image.target }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Install cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Sign image with cosign
env:
COSIGN_EXPERIMENTAL: "1"
TAGS: ${{ steps.meta.outputs.tags }}
GH_REPO: ${{ github.repository }}
GH_WORKFLOW: ${{ github.workflow }}
GH_SHA: ${{ github.sha }}
IMAGE_DIGEST: ${{ steps.image.outputs.digest }}
run: |
mapfile -t TAG_LIST <<< "$TAGS"
for tag in "${TAG_LIST[@]}"; do
cosign sign \
-a "repo=${GH_REPO}" \
-a "workflow=${GH_WORKFLOW}" \
-a "sha=${GH_SHA}" \
--yes \
"${tag}@${IMAGE_DIGEST}"
done
- name: Extract first tag
id: first-tag
env:
TAGS: ${{ steps.meta.outputs.tags }}
run: |
mapfile -t TAG_LIST <<< "$TAGS"
echo "tag=${TAG_LIST[0]}" >> "$GITHUB_OUTPUT"
- name: Generate SBOM
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
image: ${{ steps.first-tag.outputs.tag }}
format: 'cyclonedx-json'
output-file: 'sbom.cyclonedx.json'
upload-release-assets: false
- name: Attest SBOM
uses: actions/attest-sbom@c604332985a26aa8cf1bdc465b92731239ec6b9e # v4.1.0
with:
subject-name: ghcr.io/${{ github.repository_owner }}/${{ matrix.image.name }}
subject-digest: ${{ steps.image.outputs.digest }}
sbom-path: 'sbom.cyclonedx.json'
push-to-registry: true
- name: Attest provenance
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ghcr.io/${{ github.repository_owner }}/${{ matrix.image.name }}
subject-digest: ${{ steps.image.outputs.digest }}
push-to-registry: true