Repository object · automation

Container

Accepted automation in the public catalog.

Source path
.github/workflows/container.yml
Media type
application/yaml
Object ID
em:automation:sha256:3a90a6127614f1a6487a4ae37ab09608f1b6486e9b32716f9be2c7ed831b9e44
Content digest
772d8067eac4691255f3bb2b3279093ff1e87d7bb00c2b4646e2720ee60b6598

Source content

name: publish-container

on:

workflow_dispatch:

inputs:

tag:

description: Existing accepted release tag to build and publish.

required: true

type: string

confirm_publish:

description: Publish the image to GHCR.

required: true

default: false

type: boolean

permissions: {}

jobs:

image:

if: github.ref == 'refs/heads/main' && inputs.confirm_publish

environment: ghcr

permissions:

contents: read

packages: write

runs-on: ubuntu-latest

timeout-minutes: 25

steps:

- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

with:

ref: ${{ inputs.tag }}

fetch-depth: 0

persist-credentials: false

- name: Verify accepted release tag

id: release

env:

RELEASE_TAG: ${{ inputs.tag }}

run: |

if [[ ! "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then

echo 'Release tag must have the exact form vMAJOR.MINOR.PATCH.'

exit 1

fi

RELEASE_SHA="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")"

test "$(git rev-parse HEAD)" = "$RELEASE_SHA"

git fetch origin main --no-tags

git merge-base --is-ancestor "$RELEASE_SHA" origin/main

SOURCE_EPOCH="$(git show -s --format=%ct "$RELEASE_SHA")"

test -n "$SOURCE_EPOCH"

echo "sha=$RELEASE_SHA" >> "$GITHUB_OUTPUT"

echo "short_sha=${RELEASE_SHA:0:12}" >> "$GITHUB_OUTPUT"

echo "source_epoch=$SOURCE_EPOCH" >> "$GITHUB_OUTPUT"

- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3

with:

registry: ghcr.io

username: ${{ github.actor }}

password: ${{ secrets.GITHUB_TOKEN }}

- uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5

id: meta

with:

images: ghcr.io/yoheinakajima/epistemedia

tags: |

type=raw,value=${{ inputs.tag }}

type=raw,value=sha-${{ steps.release.outputs.short_sha }}

- uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6

with:

context: .

build-args: |

EPISTEMEDIA_ACCEPTED_COMMIT=${{ steps.release.outputs.sha }}

SOURCE_DATE_EPOCH=${{ steps.release.outputs.source_epoch }}

push: true

tags: ${{ steps.meta.outputs.tags }}

labels: ${{ steps.meta.outputs.labels }}

provenance: mode=max

sbom: true

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0