Repository object · automation
Container
Accepted automation in the public catalog.
- Source path
.github/workflows/container.yml- Media type
application/yaml- Object ID
em:automation:sha256:3a90a6127614f1a6487a4ae37ab09608f1b6486e9b32716f9be2c7ed831b9e44- Content digest
772d8067eac4691255f3bb2b3279093ff1e87d7bb00c2b4646e2720ee60b6598
Source content
name: publish-container
on:
workflow_dispatch:
inputs:
tag:
description: Existing accepted release tag to build and publish.
required: true
type: string
confirm_publish:
description: Publish the image to GHCR.
required: true
default: false
type: boolean
permissions: {}
jobs:
image:
if: github.ref == 'refs/heads/main' && inputs.confirm_publish
environment: ghcr
permissions:
contents: read
packages: write
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ inputs.tag }}
fetch-depth: 0
persist-credentials: false
- name: Verify accepted release tag
id: release
env:
RELEASE_TAG: ${{ inputs.tag }}
run: |
if [[ ! "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo 'Release tag must have the exact form vMAJOR.MINOR.PATCH.'
exit 1
fi
RELEASE_SHA="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")"
test "$(git rev-parse HEAD)" = "$RELEASE_SHA"
git fetch origin main --no-tags
git merge-base --is-ancestor "$RELEASE_SHA" origin/main
SOURCE_EPOCH="$(git show -s --format=%ct "$RELEASE_SHA")"
test -n "$SOURCE_EPOCH"
echo "sha=$RELEASE_SHA" >> "$GITHUB_OUTPUT"
echo "short_sha=${RELEASE_SHA:0:12}" >> "$GITHUB_OUTPUT"
echo "source_epoch=$SOURCE_EPOCH" >> "$GITHUB_OUTPUT"
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
id: meta
with:
images: ghcr.io/yoheinakajima/epistemedia
tags: |
type=raw,value=${{ inputs.tag }}
type=raw,value=sha-${{ steps.release.outputs.short_sha }}
- uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
build-args: |
EPISTEMEDIA_ACCEPTED_COMMIT=${{ steps.release.outputs.sha }}
SOURCE_DATE_EPOCH=${{ steps.release.outputs.source_epoch }}
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
provenance: mode=max
sbom: true
Build receipt
Reproduce this projection
- Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d- Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf- Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9- Epistemic policy
commons-balanced-v0.1- Disclosure policy
public-noninterference-v0.1- Compiler
epistemedia/0.2.0