build #566
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: build | |
| on: | |
| push: | |
| paths-ignore: | |
| - README.md | |
| branches: | |
| - main | |
| - "feature/*" | |
| - "bugfix/*" | |
| tags: | |
| - "*.*.*" | |
| pull_request: | |
| branches: | |
| - main | |
| schedule: | |
| # weekly: at 04:13 on Monday | |
| - cron: "13 4 * * 1" | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build: | |
| permissions: | |
| packages: write | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Set up Docker | |
| uses: docker/setup-docker-action@v5 | |
| with: | |
| daemon-config: | | |
| { | |
| "features": { | |
| "containerd-snapshotter": true | |
| } | |
| } | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4 | |
| with: | |
| driver: docker-container | |
| platforms: linux/arm/v7,linux/amd64,linux/arm64,linux/ppc64le,linux/riscv64,linux/s390x | |
| - name: Setup Template Dockerfiles | |
| uses: tgagor/template-dockerfiles@v0.17.17 | |
| - name: Build on pull request | |
| if: github.event_name == 'pull_request' | |
| run: | | |
| td --config build-ghcr.yaml \ | |
| --engine buildx \ | |
| --build \ | |
| --tag ${{ github.sha }} \ | |
| --delete | |
| - name: Build, squash and push | |
| if: github.event_name != 'pull_request' | |
| run: | | |
| echo ${{ secrets.CR_PAT }} | docker login ghcr.io -u $GITHUB_ACTOR --password-stdin | |
| td --config build-ghcr.yaml \ | |
| --engine buildx \ | |
| --build \ | |
| --push \ | |
| --tag ${{ github.sha }} \ | |
| --delete | |
| security-scan: | |
| permissions: | |
| security-events: write | |
| runs-on: ubuntu-latest | |
| needs: | |
| - build | |
| if: github.ref == 'refs/heads/main' || github.event_name == 'schedule' | |
| strategy: | |
| matrix: | |
| tag: | |
| - stream9 | |
| # - stream10 # temporarily disabled due to trivy issues | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Fetch image | |
| run: | | |
| echo ${{ secrets.CR_PAT }} | docker login ghcr.io -u $GITHUB_ACTOR --password-stdin | |
| set -x | |
| docker pull ghcr.io/tgagor/centos:${{ github.sha }}-${{ matrix.tag }} | |
| - name: Run Trivy vulnerability scanner | |
| uses: aquasecurity/trivy-action@v0.36.0 | |
| with: | |
| image-ref: ghcr.io/tgagor/centos:${{ github.sha }}-${{ matrix.tag }} | |
| format: template | |
| template: "@/contrib/sarif.tpl" | |
| # don't fail | |
| exit-code: 0 | |
| output: trivy-results.sarif | |
| severity: CRITICAL,HIGH,MEDIUM | |
| - name: Upload Trivy scan results to GitHub Security tab | |
| if: github.ref == 'refs/heads/main' | |
| uses: github/codeql-action/upload-sarif@v4.37.3 | |
| with: | |
| sarif_file: trivy-results.sarif | |
| publish: | |
| permissions: | |
| contents: write | |
| packages: write | |
| runs-on: ubuntu-latest | |
| needs: | |
| - build | |
| if: github.ref == 'refs/heads/main' | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Set up Docker | |
| uses: docker/setup-docker-action@v5 | |
| with: | |
| daemon-config: | | |
| { | |
| "features": { | |
| "containerd-snapshotter": true | |
| } | |
| } | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4 | |
| with: | |
| driver: docker-container | |
| platforms: linux/arm/v7,linux/amd64,linux/arm64,linux/ppc64le,linux/riscv64,linux/s390x | |
| - name: Setup Template Dockerfiles | |
| uses: tgagor/template-dockerfiles@v0.17.17 | |
| - name: Bump version and push tag | |
| id: tag_version | |
| uses: mathieudutour/github-tag-action@v6.2 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Extract version from tag on main | |
| env: | |
| VERSION_TAG: ${{ steps.tag_version.outputs.new_tag }} | |
| run: echo "DOCKER_TAG=${VERSION_TAG#v}" >> $GITHUB_ENV | |
| - name: Rebuild for Docker Hub and Push | |
| if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request' | |
| run: | | |
| echo ${{ secrets.HUB_ACCESS }} | docker login -u $GITHUB_ACTOR --password-stdin | |
| td --config build-hub.yaml \ | |
| --engine buildx \ | |
| --build \ | |
| --push \ | |
| --tag ${{ steps.tag_version.outputs.new_tag }} \ | |
| --delete | |
| - name: Install TPL | |
| if: ${{ !contains(github.event.commits[0].message, 'auto-update README') }} | |
| uses: zooplus/tpl@v0.13.8 | |
| - name: Update README | |
| if: ${{ !contains(github.event.commits[0].message, 'auto-update README') }} | |
| run: | | |
| export DOCKER_TAG=${DOCKER_TAG} | |
| tpl -t README-TEMPLATE.md | tee README.md | |
| if [[ "$(git status --porcelain)" != "" ]]; then | |
| git config user.name "GitHub Action" | |
| git config user.email "action@github.com" | |
| git add . | |
| git commit -m "docs(readme): auto-update README.md" | |
| git push | |
| fi | |
| - name: Create normal GitHub release | |
| if: github.event_name != 'schedule' || github.actor == 'dependabot[bot]' | |
| uses: actions/create-release@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| tag_name: ${{ steps.tag_version.outputs.new_tag }} | |
| release_name: Release ${{ steps.tag_version.outputs.new_tag }} | |
| body: ${{ steps.tag_version.outputs.changelog }} | |
| - name: Get current date | |
| if: github.event_name == 'schedule' && github.actor != 'dependabot[bot]' | |
| id: date | |
| run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT | |
| - name: Create a weekly GitHub release | |
| if: github.event_name == 'schedule' && github.actor != 'dependabot[bot]' | |
| uses: actions/create-release@v1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| with: | |
| tag_name: ${{ steps.tag_version.outputs.new_tag }} | |
| release_name: Release ${{ steps.tag_version.outputs.new_tag }} | |
| body: | | |
| Weekly rebuild on ${{ steps.date.outputs.date }} |