fix(ci): harden against template injection and credential exposure #47
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ci | |
| on: | |
| pull_request: | |
| env: | |
| IMAGE_REPO: ttl.sh/test-${{ github.job }}-${{ github.run_id }} | |
| APKO_CONFIG: https://raw.githubusercontent.com/chainguard-dev/apko/refs/heads/main/examples/nginx.yaml | |
| permissions: {} | |
| jobs: | |
| ci: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read # Clone the repository | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 | |
| with: | |
| persist-credentials: false | |
| - name: Build, sign, inspect an image using wolfi-act | |
| uses: ./ | |
| with: | |
| packages: curl,apko,cosign,crane,grype,trivy | |
| command: | | |
| set -x | |
| # Download an apko config file | |
| curl -L -o apko.yaml "${APKO_CONFIG}" | |
| # Publish image using apko | |
| apko publish apko.yaml "${IMAGE_REPO}" \ | |
| --repository-append=https://packages.wolfi.dev/os \ | |
| --keyring-append=https://packages.wolfi.dev/os/wolfi-signing.rsa.pub \ | |
| --package-append=wolfi-baselayout,nginx \ | |
| --arch=x86_64,aarch64 \ | |
| --image-refs=apko.images.txt | tee apko.index.txt | |
| index_digest="$(cat apko.index.txt)" | |
| # Scan image with grype and trivy | |
| grype "${index_digest}" | |
| trivy image "${index_digest}" | |
| # Tag image using crane | |
| crane cp "${index_digest}" "${IMAGE_REPO}:latest" | |
| - name: Make sure the image runs | |
| run: | | |
| set -x | |
| docker run --rm --entrypoint /usr/sbin/nginx "${IMAGE_REPO}:latest" -v | |
| ci-debug: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read # Clone the repository | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3 | |
| with: | |
| persist-credentials: false | |
| - name: Build, sign, inspect an image using wolfi-act | |
| uses: ./ | |
| with: | |
| debug: "true" | |
| packages: curl,apko,cosign,crane,grype,trivy | |
| command: | | |
| set -x | |
| # Download an apko config file | |
| curl -L -o apko.yaml "${APKO_CONFIG}" | |
| # Publish image using apko | |
| apko publish apko.yaml "${IMAGE_REPO}" \ | |
| --repository-append=https://packages.wolfi.dev/os \ | |
| --keyring-append=https://packages.wolfi.dev/os/wolfi-signing.rsa.pub \ | |
| --package-append=wolfi-baselayout,nginx \ | |
| --arch=x86_64,aarch64 \ | |
| --image-refs=apko.images.txt | tee apko.index.txt | |
| index_digest="$(cat apko.index.txt)" | |
| # Scan image with grype and trivy | |
| grype "${index_digest}" | |
| trivy image "${index_digest}" | |
| # Tag image using crane | |
| crane cp "${index_digest}" "${IMAGE_REPO}:latest" | |
| - name: Make sure the image runs | |
| run: | | |
| set -x | |
| docker run --rm --entrypoint /usr/sbin/nginx "${IMAGE_REPO}:latest" -v |