Skip to content

feat: tarball checksum enforcement #56

feat: tarball checksum enforcement

feat: tarball checksum enforcement #56

name: 📦 Docker Release
on:
push:
branches: [main]
tags:
- 'v*.*.*'
concurrency:
cancel-in-progress: true
group: ${{ github.workflow }}-${{ github.ref_name }}
jobs:
build-and-push-image:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
image:
- name: api
repository: ghcr.io/socialgouv/no-package-malware-api
target: api-runtime
- name: app
repository: ghcr.io/socialgouv/no-package-malware-app
target: app-runtime
- name: registry
repository: ghcr.io/socialgouv/no-package-malware-registry
target: registry-runtime
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Extract Git Tag
id: get_tag
run: |
if [[ ${{ github.ref }} == refs/tags/* ]]; then
echo "GIT_TAG=${GITHUB_REF#refs/tags/}" >> $GITHUB_OUTPUT
else
echo "GIT_TAG=$(git describe --tags --abbrev=0 || echo 'v0.0.0')" >> $GITHUB_OUTPUT
fi
- name: Log in to the Container registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata (tags, labels)
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ matrix.image.repository }}
tags: |
type=schedule
type=ref,event=branch
type=ref,event=pr
type=semver,pattern=v{{version}}
type=semver,pattern=v{{major}}.{{minor}}
type=semver,pattern=v{{major}}
type=sha
type=raw,value=latest,enable=${{ github.ref == format('refs/heads/{0}', github.event.repository.default_branch) }}
- name: Build and push ${{ matrix.image.name }} image
uses: docker/build-push-action@v6
with:
context: .
file: Dockerfile
target: ${{ matrix.image.target }}
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
build-args: |
VERSION=${{ steps.get_tag.outputs.GIT_TAG }}