Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 0 additions & 3 deletions .eslintrc.json
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,6 @@
"camelcase": "off",
"@typescript-eslint/consistent-type-assertions": "error",
"@typescript-eslint/explicit-function-return-type": ["error", {"allowExpressions": true}],
"@typescript-eslint/func-call-spacing": ["error", "never"],
"@typescript-eslint/no-array-constructor": "error",
"@typescript-eslint/no-empty-interface": "error",
"@typescript-eslint/no-explicit-any": "error",
Expand All @@ -43,8 +42,6 @@
"@typescript-eslint/require-array-sort-compare": "error",
"@typescript-eslint/restrict-plus-operands": "error",
"semi": "off",
"@typescript-eslint/semi": ["error", "never"],
"@typescript-eslint/type-annotation-spacing": "error",
"@typescript-eslint/unbound-method": "error"
},
"env": {
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
name: Tests

on: ['push']

permissions:
contents: read

jobs:
tag-push:
name: Test Copy Operation
runs-on: ubuntu-latest
env:
REGISTRY_USER: testuser
REGISTRY_PASSWORD: testpassword
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Start authenticated registry
run: |
mkdir -p "$RUNNER_TEMP/auth"
docker run --rm --entrypoint htpasswd httpd:2 \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply-chain risk: httpd:2 is not pinned to a SHA digest. A compromised or updated image could silently affect CI runs. Pin it to a specific digest, e.g.:

Suggested change
docker run --rm --entrypoint htpasswd httpd:2 \
docker run --rm --entrypoint htpasswd httpd:2.4.62@sha256:<digest> \

Run docker pull httpd:2 && docker inspect httpd:2 --format='{{index .RepoDigests 0}}' to get the current digest.

-Bbn "$REGISTRY_USER" "$REGISTRY_PASSWORD" > "$RUNNER_TEMP/auth/htpasswd"
docker run -d --restart=always \
--name registry \
-p 5001:5000 \
-v "$RUNNER_TEMP/auth:/auth" \
-e REGISTRY_AUTH=htpasswd \
-e "REGISTRY_AUTH_HTPASSWD_REALM=Registry Realm" \
-e REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd \
docker.io/distribution/distribution:3

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Supply-chain risk: docker.io/distribution/distribution:3 is not pinned to a SHA digest. Pin it to a specific digest to prevent silent image substitution in CI.

# Wait until the registry answers (401 = up and asking for auth).
for i in $(seq 1 30); do
code=$(curl -s -o /dev/null -w '%{http_code}' "http://localhost:5001/v2/" || true)
[ "$code" != "000" ] && break
sleep 1
done

- name: Login to registry
run: |
echo "$REGISTRY_PASSWORD" | \
docker login localhost:5001 -u "$REGISTRY_USER" --password-stdin

- name: Copy image to the registry
uses: ./
with:
src: docker.io/library/busybox:latest
dst: |
localhost:5001/busybox:ci

- name: Verify pushed image
# The copied image must be byte-identical to the source, so their
# (content-addressed) image IDs have to match.
run: |
docker pull busybox:latest
docker pull localhost:5001/busybox:ci
SRC_ID=$(docker images -q busybox:latest)
DST_ID=$(docker images -q localhost:5001/busybox:ci)
echo "pushed image: ${DST_ID} (expected ${SRC_ID})"
test "$SRC_ID" = "$DST_ID"

test3:
name: Unit Test
runs-on: ubuntu-latest
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@5ef0c079ce82195b2a36a210272d6b661572d83e # v2.14.2
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: Install
run: npm install

- name: Test
run: npm test

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing newline at end of file — the last line of ci.yml has no trailing newline (\ No newline at end of file in the diff). Add a newline after npm test.

3 changes: 2 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -96,4 +96,5 @@ Thumbs.db

# Ignore built ts files
__tests__/runner/*
lib/**/*
lib/**/*
.idea
Loading
Loading