Skip to content

Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#269) #176

Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#269)

Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#269) #176

Workflow file for this run

name: Publish Docker images (GHCR)
on: # yamllint disable-line rule:truthy
push:
branches:
- main
env:
REMOTE_IMAGE: ghcr.io/dependabot/proxy
permissions: {}
jobs:
publish:
name: Build and publish Docker images
runs-on: ubuntu-latest
if: github.repository == 'dependabot/proxy'
permissions:
contents: write
packages: write
id-token: write
attestations: write
artifact-metadata: write
steps:
- name: Check out code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Log in to GHCR
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set version tag
run: |
VERSION="v2.0.$(date -u +%Y%m%d%H%M%S)"
echo "VERSION=$VERSION" >> "$GITHUB_ENV"
- name: Build and push image
id: build
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: true
tags: |
${{ env.REMOTE_IMAGE }}:${{ env.VERSION }}
${{ env.REMOTE_IMAGE }}:latest
platforms: linux/amd64
build-args: GIT_COMMIT=${{ github.sha }}
cache-to: type=inline
outputs: type=image,oci-mediatypes=false
# Generate signed provenance separately without changing the image manifest.
provenance: false
sbom: false
- name: Require image digest
env:
IMAGE_DIGEST: ${{ steps.build.outputs.digest }}
run: ': "${IMAGE_DIGEST:?Build returned no image digest}"'
- name: Generate artifact attestation
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-name: ${{ env.REMOTE_IMAGE }}
subject-digest: ${{ steps.build.outputs.digest }}
push-to-registry: true
- name: Create Git tag
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
IMAGE_DIGEST: ${{ steps.build.outputs.digest }}
run: |
set -euo pipefail
gh api --method POST "repos/${GITHUB_REPOSITORY}/git/refs" \
-f "ref=refs/tags/${VERSION}" \
-f "sha=${GITHUB_SHA}" \
--silent
{
printf 'Published `%s:%s` and `%s:latest`\n\n' "$REMOTE_IMAGE" "$VERSION" "$REMOTE_IMAGE"
printf 'Digest: `%s`\n\n' "$IMAGE_DIGEST"
printf 'Source commit: `%s`\n\n' "$GITHUB_SHA"
} >> "$GITHUB_STEP_SUMMARY"