forked from ZoeyVid/NPMplus
-
Notifications
You must be signed in to change notification settings - Fork 0
130 lines (127 loc) · 5.78 KB
/
Copy pathdocker-develop.yml
File metadata and controls
130 lines (127 loc) · 5.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
name: Build Develop Docker Image
on:
push:
branches:
- develop
pull_request:
workflow_dispatch:
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
jobs:
build-x86_64:
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' }}
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
with:
driver-opts: env.BUILDKIT_STEP_LOG_MAX_SIZE=-1
- name: ghcr.io-login
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: ${{ github.event_name != 'pull_request' }}
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ github.token }}
- name: version
run: |
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' frontend/package.json > frontend/package.json.tmp && mv frontend/package.json.tmp frontend/package.json
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' backend/package.json > backend/package.json.tmp && mv backend/package.json.tmp backend/package.json
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
tags: ghcr.io/${{ github.repository_owner }}/npmplus:develop-x86_64
labels: |
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.revision=${{ github.sha }}
build-args: |
FLAGS=-march=x86-64-v2 -mtune=generic -fcf-protection=full
build-aarch64:
runs-on: ubuntu-26.04-arm
if: ${{ github.event_name != 'pull_request' }}
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
with:
driver-opts: env.BUILDKIT_STEP_LOG_MAX_SIZE=-1
- name: ghcr.io-login
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: ${{ github.event_name != 'pull_request' }}
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ github.token }}
- name: version
run: |
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' frontend/package.json > frontend/package.json.tmp && mv frontend/package.json.tmp frontend/package.json
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' backend/package.json > backend/package.json.tmp && mv backend/package.json.tmp backend/package.json
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
tags: ghcr.io/${{ github.repository_owner }}/npmplus:develop-aarch64
labels: |
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.revision=${{ github.sha }}
build-args: |
FLAGS=-mbranch-protection=standard
build-pr:
runs-on: ubuntu-latest
if: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
packages: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
with:
driver-opts: env.BUILDKIT_STEP_LOG_MAX_SIZE=-1
- name: version
run: |
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' frontend/package.json > frontend/package.json.tmp && mv frontend/package.json.tmp frontend/package.json
jq --arg v "$(git rev-parse --short HEAD)" '.version = $v' backend/package.json > backend/package.json.tmp && mv backend/package.json.tmp backend/package.json
- uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
push: false
load: true
tags: npmplus:pr
build-args: |
FLAGS=-march=x86-64-v2 -mtune=generic -fcf-protection=full
- name: Scan pull-request image
run: |
docker run --rm \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$PWD:/workspace" \
aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 image \
--scanners vuln \
--severity HIGH,CRITICAL \
--ignorefile /workspace/.trivy/npmplus.yaml \
--exit-code 1 \
npmplus:pr
merge:
runs-on: ubuntu-slim
permissions:
packages: write
needs: [build-x86_64, build-aarch64]
if: ${{ github.event_name != 'pull_request' }}
steps:
- name: ghcr.io-login
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ github.token }}
- name: merge
run: |
docker buildx imagetools create --tag ghcr.io/${{ github.repository_owner }}/npmplus:develop ghcr.io/${{ github.repository_owner }}/npmplus:develop-x86_64 ghcr.io/${{ github.repository_owner }}/npmplus:develop-aarch64
docker buildx imagetools create --tag ghcr.io/${{ github.repository_owner }}/npmplus:${{ github.sha }} ghcr.io/${{ github.repository_owner }}/npmplus:develop-x86_64 ghcr.io/${{ github.repository_owner }}/npmplus:develop-aarch64