name: Build and push image on: push: branches: [main] tags: ["v*"] pull_request: branches: [main] workflow_dispatch: {} # Pushes to main only run the tests. An image is built for version tags and # manual runs. permissions: contents: read env: # Spelled out rather than derived from github.repository_owner: container # registries reject upper case in an image name, and the owner has it. IMAGE: ghcr.io/tom-joad/cf-managed-network-endpoint # Actions are pinned to commit SHAs, not tags: a tag is mutable, so `@v7` # means "whatever that repo points it at today". The trailing comment records # which release each SHA corresponds to. jobs: test: runs-on: ubuntu-latest permissions: contents: read # gitleaks-action lists a pull request's commits through the API; # without this, every pull request (Dependabot's included) fails. pull-requests: read steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 # gitleaks needs history to scan past commits - name: Build the image run: docker build --tag cfmne:test . - name: Smoke test run: tests/smoke.sh cfmne:test - name: Scan for secrets uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} build: # Nothing reaches the registry unless the smoke test and the secret scan # pass first. needs: test if: startsWith(github.ref, 'refs/tags/v') || github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest permissions: contents: read packages: write id-token: write steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 # NAS and home servers are often ARM boxes, not the amd64 runner this # builds on. - name: Set up QEMU uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 - name: Set up Docker Buildx uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: Log in to GHCR uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Docker metadata id: meta uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: ${{ env.IMAGE }} tags: | type=semver,pattern={{version}} type=semver,pattern={{major}}.{{minor}} type=sha type=raw,value=latest,enable={{is_default_branch}} - name: Build and push id: build uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7 with: context: . platforms: linux/amd64,linux/arm64 push: true provenance: mode=max sbom: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} - name: Scan the built image uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 with: image-ref: ${{ env.IMAGE }}@${{ steps.build.outputs.digest }} format: table severity: HIGH,CRITICAL ignore-unfixed: true exit-code: "0" # report only: a new base-image CVE shouldn't block a security fix from shipping - name: Install cosign uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - name: Sign image (keyless, GitHub OIDC) env: IMAGE: ${{ env.IMAGE }} DIGEST: ${{ steps.build.outputs.digest }} run: cosign sign --yes "${IMAGE}@${DIGEST}"