Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
3e5674d
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 1, 2026
04d1ec2
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 1, 2026
ff2f400
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 2, 2026
4da7cd6
chore(deps): update github/codeql-action digest to 54f647b (main) (#2…
ubot-7274[bot] Jul 2, 2026
4da9a8c
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 3, 2026
a5a1816
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 3, 2026
697d03a
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 3, 2026
a6afd2a
chore: bump ubuntu runner to 26.04 for image build (#2367)
renner0e Jul 3, 2026
16d6d18
fix(ci): proper variables/names for ghcr (#2493)
renner0e Jul 3, 2026
79db718
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 3, 2026
0f9da15
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 4, 2026
ca167c7
fix: relink rpm-ostree-base-db to system rpmdb (#2499)
renner0e Jul 4, 2026
a2a6ec0
fix(just): ghcr variable is shell (#2497)
renner0e Jul 4, 2026
c0b17a5
fix(ci): fix the backport action to use the base ref (#2503)
inffy Jul 4, 2026
a51222d
chore: trim whitespace in image-versions.yml (#2498)
renner0e Jul 4, 2026
1d023a7
fix(ci): make kernel pin work from CLI (#2495)
renner0e Jul 4, 2026
4c91c48
feat(ci): rootless CI (#2496)
renner0e Jul 4, 2026
7f6154a
fix(just): disk-image recipe (#2508)
renner0e Jul 4, 2026
df43bbe
feat(ci): retries for pulled images (#2504)
renner0e Jul 4, 2026
6af2b27
feat(ci): package cache with OCI artifacts (#2466)
renner0e Jul 4, 2026
573d2c6
chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to 799…
ubot-7274[bot] Jul 5, 2026
32a8039
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 5, 2026
12917e0
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 6, 2026
7a5c941
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 6, 2026
a6e3750
chore(deps): update ghcr.io/get-aurora-dev/common:latest docker diges…
ubot-7274[bot] Jul 6, 2026
1c4a49c
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 7, 2026
838bc78
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 8, 2026
e99cd4c
chore(deps): update github/codeql-action digest to 99df26d (main) (#2…
ubot-7274[bot] Jul 8, 2026
e76ddc0
chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to fb4…
ubot-7274[bot] Jul 8, 2026
5875408
chore(ci): remove build all images workflow (#2527)
renner0e Jul 8, 2026
8b90b58
chore(ci): tighten image build workflows permissions (#2526)
renner0e Jul 8, 2026
ba681da
chore(ci): use built-in release function of gh (#2532)
renner0e Jul 8, 2026
2e7a411
chore(ci): mitigate script injection attacks in generate-release (#2531)
renner0e Jul 8, 2026
97ad970
chore(ci): do not persist credentials in git checkout (#2530)
renner0e Jul 8, 2026
1a5d394
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 9, 2026
d818c4e
chore(ci): tighten secret usage (#2537)
renner0e Jul 9, 2026
b0b1fc0
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 10, 2026
5659fbc
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 11, 2026
4b89939
chore(deps): update oras-project/setup-oras action to v2.0.1 (#2543)
ubot-7274[bot] Jul 11, 2026
d015b6b
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 12, 2026
adac845
chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to ff8…
ubot-7274[bot] Jul 12, 2026
ca6ff84
feat(chunkah): use oci-dir instead of tar-roundtrip (#2545)
renner0e Jul 12, 2026
7581e88
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 13, 2026
a925e02
feat(ci): setup runner with containers policy (#2549)
renner0e Jul 13, 2026
74a7581
chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker …
ubot-7274[bot] Jul 14, 2026
dc837eb
chore(deps): update actions/setup-node action to v7 (#2556)
ubot-7274[bot] Jul 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 34 additions & 0 deletions .github/setup-runner-keys.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
#!/usr/bin/env bash

# Setup Public Keys for containers that are pulled during the build

set -eoux pipefail

PKI_DIR="/etc/pki/containers"
REGISTRIES="/etc/containers/registries.d"

mkdir -p "${PKI_DIR}" "${REGISTRIES}"
cp cosign.pub "${PKI_DIR}/ghcr.io-ublue-os.pub"
cp quay.io-fedora-ostree-desktops.pub "${PKI_DIR}"

yq -n '.docker."ghcr.io/ublue-os".use-sigstore-attachments = true' | tee "${REGISTRIES}"/ublue-os.yaml
yq -n '.docker."quay.io/fedora-ostree-desktops".use-sigstore-attachments = true' | tee "${REGISTRIES}"/fedora-ostree-desktops.yaml

jq '.transports.docker["ghcr.io/ublue-os"] = [
{
"type": "sigstoreSigned",
"keyPath": "/etc/pki/containers/ghcr.io-ublue-os.pub",
"signedIdentity": {
"type": "matchRepository"
}
}
] |
.transports.docker["quay.io/fedora-ostree-desktops"] = [
{
"type": "sigstoreSigned",
"keyPath": "/etc/pki/containers/quay.io-fedora-ostree-desktops.pub",
"signedIdentity": {
"type": "matchRepository"
}
}
]' /etc/containers/policy.json | tee /etc/containers/policy.json.tmp > /dev/null && mv /etc/containers/policy.json.tmp /etc/containers/policy.json
17 changes: 9 additions & 8 deletions .github/workflows/build-image-latest-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,18 +20,20 @@ on:
workflow_call:
workflow_dispatch:

permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
permissions: {}

jobs:
build-image-latest:
name: Build Latest Images
uses: ./.github/workflows/reusable-build.yml
secrets: inherit
permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
secrets:
SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }}
strategy:
fail-fast: false
matrix:
Expand All @@ -51,7 +53,6 @@ jobs:
needs: [build-image-latest]
permissions:
contents: write
secrets: inherit
uses: ./.github/workflows/generate-release.yml
with:
stream_name: '["latest"]'
17 changes: 9 additions & 8 deletions .github/workflows/build-image-stable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,18 +14,20 @@ on:
workflow_call:
workflow_dispatch:

permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
permissions: {}

jobs:
build-image-stable:
name: Build Stable Images
uses: ./.github/workflows/reusable-build.yml
secrets: inherit
permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
secrets:
SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }}
strategy:
fail-fast: false
matrix:
Expand All @@ -43,7 +45,6 @@ jobs:
needs: [build-image-stable]
permissions:
contents: write
secrets: inherit
uses: ./.github/workflows/generate-release.yml
with:
stream_name: '["stable"]'
16 changes: 9 additions & 7 deletions .github/workflows/build-image-testing.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,18 +11,20 @@ on:
workflow_call:
workflow_dispatch:

permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
permissions: {}

jobs:
build-image-testing:
name: Build Testing Images
uses: ./.github/workflows/reusable-build.yml
secrets: inherit
permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
secrets:
SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }}
strategy:
fail-fast: false
matrix:
Expand Down
27 changes: 0 additions & 27 deletions .github/workflows/build-images.yml

This file was deleted.

5 changes: 5 additions & 0 deletions .github/workflows/cherry-pick-to-stable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,13 @@ jobs:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false
# Use the dynamically generated GitHub App token
token: ${{ steps.generate-token.outputs.token }}
# Explicitly check out the base branch (the PR is already merged into it).
# Avoids the default `refs/pull/<PR>/merge` ref, which actions/checkout
# refuses to check out for fork PRs on pull_request_target events.
ref: ${{ github.event.pull_request.base.ref }}
fetch-depth: 0

- name: Configure Git Author
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/clean.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,11 @@ jobs:
delete-orphaned-images: true
keep-n-tagged: 7
keep-n-untagged: 7

- name: Delete All OCI Artifact Cache
uses: dataaxiom/ghcr-cleanup-action@d52806a0dc70b430571a37da1fde39733ffd640f # v1.2.2
with:
token: ${{ secrets.GITHUB_TOKEN }}
packages: aurora/cache/dnf
keep-n-tagged: 1
older-than: 90 days
25 changes: 16 additions & 9 deletions .github/workflows/generate-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ jobs:
- name: Checkout last 500 commits (for <commits> to work)
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false
fetch-depth: 500
ref: stable-f44

Expand All @@ -47,23 +48,29 @@ jobs:
just check

- name: Install ORAS
uses: oras-project/setup-oras@38de303aac69abb66f3e6255b7198bff35f323e3 # v2.0.0
uses: oras-project/setup-oras@1d808f7d7f6995cc68b7bf507bfe5c5446e1dc9d # v2.0.1

- name: Generate Release Text
id: generate-release-text
env:
MATRIX_VERSION: "${{ matrix.version }}"
HANDWRITTEN: "${{ inputs.handwritten }}"
shell: bash
run: |
just changelogs "${{ matrix.version }}" "${{ inputs.handwritten }}"
just changelogs "${MATRIX_VERSION}" "${HANDWRITTEN}"
source ./output.env
echo "title=${TITLE}" >> $GITHUB_OUTPUT
echo "tag=${TAG}" >> $GITHUB_OUTPUT

- name: Create Release
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3
if: contains(fromJson('["stable"]'), matrix.version) && (github.event.schedule == '0 1 * * TUE' || contains(fromJson('["workflow_dispatch", "workflow_call"]'), github.event_name))
with:
name: ${{ steps.generate-release-text.outputs.title }}
tag_name: ${{ steps.generate-release-text.outputs.tag }}
body_path: ./changelog.md
make_latest: ${{ matrix.version == 'stable' }}
prerelease: false
env:
TITLE: ${{ steps.generate-release-text.outputs.title }}
TAG: ${{ steps.generate-release-text.outputs.tag }}
BODY_PATH: ./changelog.md
run: |
gh release create \
"${TAG}" \
--title "${TITLE}" \
-F "${BODY_PATH}" \
--latest
3 changes: 3 additions & 0 deletions .github/workflows/moderator.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@ jobs:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false

- uses: github/ai-moderator@81159c370785e295c97461ade67d7c33576e9319 # v1
with:
token: ${{ secrets.GITHUB_TOKEN }}
Expand Down
Loading
Loading