From 3e5674d5427fdbd6d730625ac05c318c5ffc18a3 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 05:02:08 +0000 Subject: [PATCH 01/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 51c7b27 (#2475) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 1de474c58..fb8c30f85 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:ce90f03230d31b85feac8334b469f9e7ad32b899488e6a7c26cab290f24d779e + digest: sha256:51c7b27b03519f890e85a66aed7ae8a52e029e5bc3a9150dba1919db4f74a586 # https://github.com/get-aurora-dev/common - name: common From 04d1ec2208c0d5cffb88f866092d9d2d2770f542 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 17:15:45 +0000 Subject: [PATCH 02/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to e7338ae (#2479) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index fb8c30f85..d068ce429 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:34ef1109a8fb08097a182ec3f184718799f48825d69cff8c97cb8a14a00bfdac + digest: sha256:e7338ae12ba14de822d8a440fbc72e6c2a463cf324727d00eb9e7717ecc4fafe # https://github.com/ublue-os/brew - name: brew From ff2f400e7ee314262e1b3727eb2e46f418bf04b8 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Thu, 2 Jul 2026 04:49:08 +0000 Subject: [PATCH 03/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 9c79b8a (#2481) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index d068ce429..1a7dc3321 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:51c7b27b03519f890e85a66aed7ae8a52e029e5bc3a9150dba1919db4f74a586 + digest: sha256:9c79b8ad727e37f14e4941dd24714640092fd164a83847e39ff1c1582c525b06 # https://github.com/get-aurora-dev/common - name: common From 4da7cd67d3d2ed52b83d30bf4a528c51873e825e Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Thu, 2 Jul 2026 13:37:04 +0300 Subject: [PATCH 04/46] chore(deps): update github/codeql-action digest to 54f647b (main) (#2483) --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 4e3e76b24..6ab65d69c 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -71,6 +71,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4 + uses: github/codeql-action/upload-sarif@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4 with: sarif_file: results.sarif From 4da9a8c9d8fb031a2cfcf0a773e6c6086cfe0d81 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Fri, 3 Jul 2026 04:45:04 +0000 Subject: [PATCH 05/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 97ae835 (#2486) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 1a7dc3321..42abde3d1 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:9c79b8ad727e37f14e4941dd24714640092fd164a83847e39ff1c1582c525b06 + digest: sha256:97ae835223c2e7b340dd5a1f8e793f62c90243d7889fdd810911f08696187400 # https://github.com/get-aurora-dev/common - name: common From a5a1816e7836437a9cc268a0dad2c86e2e84164a Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Fri, 3 Jul 2026 06:57:25 +0000 Subject: [PATCH 06/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to a93e788 (#2488) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 42abde3d1..483f62656 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:e7338ae12ba14de822d8a440fbc72e6c2a463cf324727d00eb9e7717ecc4fafe + digest: sha256:a93e788b1ff50371b56c25d53d6bd00a88381afd4e53904b4b81d86222b27fc4 # https://github.com/ublue-os/brew - name: brew From 697d03ac72d8f130bb9f6b11af457347e480d2db Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Fri, 3 Jul 2026 09:02:46 +0000 Subject: [PATCH 07/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to 390a9dc (#2490) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 483f62656..858ebeaa3 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:a93e788b1ff50371b56c25d53d6bd00a88381afd4e53904b4b81d86222b27fc4 + digest: sha256:390a9dcd8c1c3a646f884b7571abb1da9b24ce99d014bf3fdbee6eae6ebac799 # https://github.com/ublue-os/brew - name: brew From a6afd2aaa773e7ac623ad680aed8e820e85275f2 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Fri, 3 Jul 2026 18:13:17 +0200 Subject: [PATCH 08/46] chore: bump ubuntu runner to 26.04 for image build (#2367) Co-authored-by: inffy <10782843+inffy@users.noreply.github.com> --- .github/workflows/reusable-build.yml | 25 +------------------------ 1 file changed, 1 insertion(+), 24 deletions(-) diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index 5be90d901..0fe080522 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -38,7 +38,7 @@ permissions: {} jobs: build_container: name: image - runs-on: ${{ matrix.architecture == 'x86_64' && 'ubuntu-24.04' || 'ubuntu-24.04-arm' }} + runs-on: ${{ matrix.architecture == 'x86_64' && 'ubuntu-26.04' || 'ubuntu-26.04-arm' }} permissions: contents: read packages: write @@ -81,29 +81,6 @@ jobs: id: remove-unwanted-software uses: ublue-os/remove-unwanted-software@695eb75bc387dbcd9685a8e72d23439d8686cba6 - # TODO: remove me when we have a new podman in 26.04 runners - # needed because old podman doesn't push layer annotations for - # the rpm-ostree rechunker at all - - name: Update podman - shell: bash - run: | - set -eux - # Require the runner is ubuntu-24.04 - IDV=$(. /usr/lib/os-release && echo ${ID}-${VERSION_ID}) - test "${IDV}" = "ubuntu-24.04" - # resolute is the next release. The azure.archive.ubuntu.com mirror only carries amd64. - # Other architectures like arm64 use ports.ubuntu.com/ubuntu-ports. - if [ "$(dpkg --print-architecture)" = "amd64" ]; then - mirror="http://azure.archive.ubuntu.com/ubuntu" - else - mirror="http://ports.ubuntu.com/ubuntu-ports" - fi - echo "deb ${mirror} resolute universe main" | sudo tee /etc/apt/sources.list.d/resolute.list - /bin/time -f '%E %C' sudo apt update - # skopeo is currently older in resolute for some reason hence --allow-downgrades - /bin/time -f '%E %C' sudo apt install -y --allow-downgrades crun/resolute buildah/resolute podman/resolute skopeo/resolute - podman --version - - name: Install Just run: | /home/linuxbrew/.linuxbrew/bin/brew install just From 16d6d18e6528f87e4a25a67ae168656618399219 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Fri, 3 Jul 2026 21:13:39 +0200 Subject: [PATCH 09/46] fix(ci): proper variables/names for ghcr (#2493) This didn't break anything in CI, this is why this went unnoticed. fixup of cfd014fa. --- Justfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Justfile b/Justfile index d71cc7d66..5b5d3b741 100644 --- a/Justfile +++ b/Justfile @@ -273,7 +273,7 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false PODMAN_BUILD_ARGS+=("--retry=5" "--retry-delay=60s") # So we always have the newest images when building locally - if [[ {{ ghcr }} == "0" ]]; then + if [[ "${ghcr}" == "false" ]]; then PODMAN_BUILD_ARGS+=("--pull=newer") fi @@ -855,7 +855,7 @@ disk-image $image="aurora" $tag="latest" $flavor="main" ghcr="false" $backend="o [arg("temp_push", long="temp-push", value="true")] [arg("temp_push_tag", long="temp-push-tag")] [group('Utility')] -push-image $image="aurora" $tag="latest" $flavor="main" $ghcr="0" $registry="" $temp_push="false" $temp_push_tag="": +push-image $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $registry="" $temp_push="false" $temp_push_tag="": #!/usr/bin/env bash set -eoux pipefail From 79db718a00620c149c20fa709f8e179086461996 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Fri, 3 Jul 2026 20:13:11 +0000 Subject: [PATCH 10/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to c00fc6b (#2494) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 858ebeaa3..af87b2d09 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:390a9dcd8c1c3a646f884b7571abb1da9b24ce99d014bf3fdbee6eae6ebac799 + digest: sha256:c00fc6bbc6c44d4438f3f93648b8f641e16add723c4b094b854e6460536050b8 # https://github.com/ublue-os/brew - name: brew From 0f9da1585637fe70dd6b2326811295ca5119ff0b Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sat, 4 Jul 2026 03:51:43 +0000 Subject: [PATCH 11/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 59c7dc8 (#2500) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index af87b2d09..130125e12 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:97ae835223c2e7b340dd5a1f8e793f62c90243d7889fdd810911f08696187400 + digest: sha256:59c7dc8dc4d1f9a86e61c3a70e4010598d8d452c533ce380ef5257e60ae05cca # https://github.com/get-aurora-dev/common - name: common From ca167c7b01922424d5e87cce5b8cad6b5b26599d Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 07:46:27 +0200 Subject: [PATCH 12/46] fix: relink rpm-ostree-base-db to system rpmdb (#2499) taken from blue-build[1], this also happens to make updates smaller by 100MB. Might fix the following issues like [2] and [3]. I could not reproduce these issues myself and just using chunkah made it possible for me to overlay firefox with rpm-ostree. [1]: https://github.com/blue-build/cli/commit/b6f36bd9a2efff30adb06cf9dba43a24d6f47891 [2]: https://github.com/ublue-os/aurora/issues/2209 [3]: https://github.com/ublue-os/aurora/issues/2492 Co-authored-by: Daniel Hast <32797673+HastD@users.noreply.github.com> --- build_files/shared/clean-stage.sh | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/build_files/shared/clean-stage.sh b/build_files/shared/clean-stage.sh index 34b192b10..d69643777 100755 --- a/build_files/shared/clean-stage.sh +++ b/build_files/shared/clean-stage.sh @@ -13,6 +13,19 @@ systemctl disable flatpak-add-fedora-repos.service systemctl mask flatpak-add-fedora-repos.service rm -f /usr/lib/systemd/system/flatpak-add-fedora-repos.service +# Relink rpm-ostree-base-db to rpmdb to ensure it correctly reflects the system +# image's rpmdb and doesn't carry over package info from the base image. +# See: https://github.com/coreos/rpm-ostree/issues/4554 +# https://forge.fedoraproject.org/atomic/tracker/issues/82 +for file in rpmdb.sqlite rpmdb.sqlite-shm rpmdb.sqlite-wal; do + target="/usr/share/rpm/${file}" + link_path="/usr/lib/sysimage/rpm-ostree-base-db/${file}" + if [[ -f "${target}" && -f "${link_path}" ]]; then + # Note, this needs to be a hardlink, not a symbolic link. + ln -f "${target}" "${link_path}" + fi +done + rm -rf /.gitkeep find /var/* -maxdepth 0 -type d \! -name cache -exec rm -fr {} \; From a2a6ec077eeece1a5096341d9fa10c97a436f629 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 11:16:14 +0200 Subject: [PATCH 13/46] fix(just): ghcr variable is shell (#2497) follow up of: 16d6d18e --- Justfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Justfile b/Justfile index 5b5d3b741..8ce2b88cd 100644 --- a/Justfile +++ b/Justfile @@ -806,7 +806,7 @@ bootc $image="aurora" $tag="latest" $flavor="main" *ARGS: [arg("image", long="image", short="i")] [arg("tag", long="tag", short="t")] [group('Utility')] -disk-image $image="aurora" $tag="latest" $flavor="main" ghcr="false" $backend="ostree": +disk-image $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $backend="ostree": #!/usr/bin/env bash set -eoux pipefail From c0b17a51a5eed4a62500510130f955bfd81aa7c7 Mon Sep 17 00:00:00 2001 From: inffy <10782843+inffy@users.noreply.github.com> Date: Sat, 4 Jul 2026 12:27:09 +0300 Subject: [PATCH 14/46] fix(ci): fix the backport action to use the base ref (#2503) --- .github/workflows/cherry-pick-to-stable.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/cherry-pick-to-stable.yml b/.github/workflows/cherry-pick-to-stable.yml index f59a3ed4a..485f20e7b 100644 --- a/.github/workflows/cherry-pick-to-stable.yml +++ b/.github/workflows/cherry-pick-to-stable.yml @@ -28,6 +28,10 @@ jobs: with: # Use the dynamically generated GitHub App token token: ${{ steps.generate-token.outputs.token }} + # Explicitly check out the base branch (the PR is already merged into it). + # Avoids the default `refs/pull//merge` ref, which actions/checkout + # refuses to check out for fork PRs on pull_request_target events. + ref: ${{ github.event.pull_request.base.ref }} fetch-depth: 0 - name: Configure Git Author From a51222dcbd4686caba8e28990f2d42d65e133771 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 11:28:39 +0200 Subject: [PATCH 15/46] chore: trim whitespace in image-versions.yml (#2498) --- image-versions.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/image-versions.yml b/image-versions.yml index 130125e12..28a0bcb01 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -5,12 +5,12 @@ images: tag: 44 digest: sha256:59c7dc8dc4d1f9a86e61c3a70e4010598d8d452c533ce380ef5257e60ae05cca - # https://github.com/get-aurora-dev/common + # https://github.com/get-aurora-dev/common - name: common image: ghcr.io/get-aurora-dev/common tag: latest digest: sha256:c00fc6bbc6c44d4438f3f93648b8f641e16add723c4b094b854e6460536050b8 - + # https://github.com/ublue-os/brew - name: brew image: ghcr.io/ublue-os/brew From 1d023a7c4f370d4618d88adef27ad3fff473ca8c Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 12:22:28 +0200 Subject: [PATCH 16/46] fix(ci): make kernel pin work from CLI (#2495) If you specified --kernel-pin from cli it will now correctly verify and donwload the right version (instead of the newest one), if it's specified in the Justfile and CLI then CLI wins. The pin that is always set to an empty string would override it. --- Justfile | 51 ++++++++++++++++++++++++++------------------------- 1 file changed, 26 insertions(+), 25 deletions(-) diff --git a/Justfile b/Justfile index 8ce2b88cd..ed55e0187 100644 --- a/Justfile +++ b/Justfile @@ -148,31 +148,32 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false # skopeo list-tags docker://ghcr.io/ublue-os/akmods | jq -r '.Tags | map(select(contains("coreos-stable-44")))' ARCH=$(arch) - - case "${tag}" in - stable) - if [[ "${ARCH}" == "x86_64" ]]; then - # - kernel_pin="" - elif [[ "${ARCH}" == "aarch64" ]]; then - kernel_pin="" - fi - ;; - latest) - if [[ "${ARCH}" == "x86_64" ]]; then - kernel_pin="" - elif [[ "${ARCH}" == "aarch64" ]]; then - kernel_pin="" - fi - ;; - testing) - if [[ "${ARCH}" == "x86_64" ]]; then - kernel_pin="" - elif [[ "${ARCH}" == "aarch64" ]]; then - kernel_pin="" - fi - ;; - esac + if [[ -z "${kernel_pin:-}" ]]; then + case "${tag}" in + stable) + if [[ "${ARCH}" == "x86_64" ]]; then + # + kernel_pin="" + elif [[ "${ARCH}" == "aarch64" ]]; then + kernel_pin="" + fi + ;; + latest) + if [[ "${ARCH}" == "x86_64" ]]; then + kernel_pin="" + elif [[ "${ARCH}" == "aarch64" ]]; then + kernel_pin="" + fi + ;; + testing) + if [[ "${ARCH}" == "x86_64" ]]; then + kernel_pin="" + elif [[ "${ARCH}" == "aarch64" ]]; then + kernel_pin="" + fi + ;; + esac + fi if [[ -z "${kernel_pin:-}" ]]; then kernel_release=$(skopeo inspect --retry-times 3 docker://ghcr.io/ublue-os/akmods:"${akmods_flavor}"-"${fedora_version}" | jq -r '.Labels["ostree.linux"]') From 4c91c4871010b5bf28bdd7e76b83e1931d52c997 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 14:15:05 +0200 Subject: [PATCH 17/46] feat(ci): rootless CI (#2496) * feat(ci): rootless CI 26.04 runners use sudo-rs, which does not support this flag. It doesn't seem to have broken too much, Only thing I could see is the github token not being passed to the build. ``` sudo: preserving the entire environment is not supported, '-E' is ignored ``` So this is a good time to move over to a rootless CI I guess. * chore: unset target-dir for container-storage-action This defaults to the user container storage --- .github/workflows/reusable-build.yml | 21 ++++++++++----------- Justfile | 2 ++ 2 files changed, 12 insertions(+), 11 deletions(-) diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index 0fe080522..fc46158ed 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -73,7 +73,6 @@ jobs: uses: ublue-os/container-storage-action@25e05be4948f77746938687877829d15c5038036 continue-on-error: true with: - target-dir: /var/lib/containers mount-opts: compress-force=zstd:2 loopback-free: '1' @@ -157,7 +156,7 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - sudo -E $(command -v just) \ + $(command -v just) \ repo_organization="${{ github.repository_owner }}" \ build \ --image "${MATRIX_BASE_NAME}" \ @@ -170,7 +169,7 @@ jobs: shell: bash id: cache-perms run: | - sudo chmod 777 --recursive /var/tmp/buildah-cache-0 + chmod 777 --recursive /var/tmp/buildah-cache-${UID} - name: Write new DNF package cache if: steps.setup-cache.outputs.allow_cache_write == 'true' @@ -188,7 +187,7 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - sudo -E $(command -v just) rechunk \ + $(command -v just) rechunk \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" @@ -207,7 +206,7 @@ jobs: MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} SYFT_CMD: ${{ steps.setup-syft.outputs.cmd }} run: | - sudo -E $(command -v just) gen-sbom \ + $(command -v just) gen-sbom \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" \ @@ -221,7 +220,7 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - sudo -E $(command -v just) secureboot \ + $(command -v just) secureboot \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" @@ -234,7 +233,7 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - sudo -E $(command -v just) export-oci \ + $(command -v just) export-oci \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" @@ -260,7 +259,7 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - sudo -E $(command -v just) disk-image \ + $(command -v just) disk-image \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" \ @@ -309,7 +308,7 @@ jobs: ALIAS_TAGS: ${{ steps.generate-tags.outputs.alias_tags }} run: | set -eoux pipefail - sudo -E $(command -v just) tag-images \ + $(command -v just) tag-images \ --image "${IMAGE_NAME}" \ --default-tag "${MATRIX_STREAM_NAME}" \ --tags "${ALIAS_TAGS}" @@ -346,7 +345,7 @@ jobs: run: | set -euox pipefail - sudo -E $(command -v just) push-image \ + $(command -v just) push-image \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" \ @@ -386,7 +385,7 @@ jobs: run: | set -euox pipefail - sudo -E $(command -v just) push-image \ + $(command -v just) push-image \ --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" \ diff --git a/Justfile b/Justfile index ed55e0187..fb0b25e37 100644 --- a/Justfile +++ b/Justfile @@ -841,6 +841,8 @@ disk-image $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $backend=" BOOTC_INSTALL_ARGS+=("--bootloader systemd" "--composefs-backend") fi + {{ just }} load-rootful --image "${image}" --tag "${tag}" --flavor "${flavor}" + {{ just }} bootc "${image}" "${tag}" "${flavor}" install to-disk "${BOOTC_INSTALL_ARGS[@]}" # FIXME: Please consider using podman push in the future for signing as well instead of temporary tag + cosign From 7f6154a54966aaa9ead3a5f8e95494d895b26391 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 21:55:15 +0200 Subject: [PATCH 18/46] fix(just): disk-image recipe (#2508) * fix(just): disk-image recipe follow up of: cfd014fa2 * run recipe as root in CI * fix: do load-rootful before disk-image --- .github/workflows/reusable-build.yml | 15 ++++++++++----- Justfile | 6 +++--- 2 files changed, 13 insertions(+), 8 deletions(-) diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index fc46158ed..795a5e26b 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -259,11 +259,16 @@ jobs: MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} run: | - $(command -v just) disk-image \ - --image "${MATRIX_BASE_NAME}" \ - --tag "${MATRIX_STREAM_NAME}" \ - --flavor "${MATRIX_IMAGE_FLAVOR}" \ - --ghcr + $(command -v just) load-rootful \ + --image "${MATRIX_BASE_NAME}" \ + --tag "${MATRIX_STREAM_NAME}" \ + --flavor "${MATRIX_IMAGE_FLAVOR}" \ + + sudo $(command -v just) disk-image \ + --image "${MATRIX_BASE_NAME}" \ + --tag "${MATRIX_STREAM_NAME}" \ + --flavor "${MATRIX_IMAGE_FLAVOR}" \ + --ghcr - name: PR Testing Instructions if: github.event_name == 'pull_request' diff --git a/Justfile b/Justfile index fb0b25e37..b9ab6a7c7 100644 --- a/Justfile +++ b/Justfile @@ -774,6 +774,7 @@ setup-cache $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $github_e echo "${CACHE_NAME}" "${ALLOW_CACHE_WRITE}" +# Example: just bootc -t testing -- --help [arg("flavor", long="flavor", short="f")] [arg("image", long="image", short="i")] [arg("tag", long="tag", short="t")] @@ -800,6 +801,7 @@ bootc $image="aurora" $tag="latest" $flavor="main" *ARGS: -v "${BUILD_BASE_DIR:-.}:/data" \ "${image_name}:${tag}" bootc {{ ARGS }} +# Example: sudo just disk-image -t testing --backend composefs # Create bootable image [arg("backend", long="backend")] [arg("flavor", long="flavor", short="f")] @@ -841,9 +843,7 @@ disk-image $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $backend=" BOOTC_INSTALL_ARGS+=("--bootloader systemd" "--composefs-backend") fi - {{ just }} load-rootful --image "${image}" --tag "${tag}" --flavor "${flavor}" - - {{ just }} bootc "${image}" "${tag}" "${flavor}" install to-disk "${BOOTC_INSTALL_ARGS[@]}" + {{ just }} bootc --image "${image}" --tag "${tag}" --flavor "${flavor}" install to-disk -- "${BOOTC_INSTALL_ARGS[@]}" # FIXME: Please consider using podman push in the future for signing as well instead of temporary tag + cosign # See: https://github.com/ublue-os/aurora/pull/2199 From df43bbeece5337b1e20e3e5459825a6dba968665 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 22:11:02 +0200 Subject: [PATCH 19/46] feat(ci): retries for pulled images (#2504) The --retry flags for podman/buildah pull/build do not seem to do anything on transient network issues. Notably our base image pull from quay is failing quite often, this should make this less likely to happen in the future. fixes: https://github.com/ublue-os/aurora/issues/2381 xref: https://github.com/ublue-os/aurora/issues/2337 --- .github/workflows/reusable-build.yml | 3 +- Justfile | 47 +++++++++++++++++++++------- 2 files changed, 38 insertions(+), 12 deletions(-) diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index 795a5e26b..a6d8e409e 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -162,7 +162,8 @@ jobs: --image "${MATRIX_BASE_NAME}" \ --tag "${MATRIX_STREAM_NAME}" \ --flavor "${MATRIX_IMAGE_FLAVOR}" \ - --ghcr + --ghcr \ + --retry-pull # https://github.com/actions/cache/issues/1533 - name: Hack around permission issue caching diff --git a/Justfile b/Justfile index b9ab6a7c7..c00875824 100644 --- a/Justfile +++ b/Justfile @@ -129,9 +129,10 @@ validate $image $tag $flavor: [arg("image", long="image", short="i")] [arg("kernel_pin", long="kernel-pin")] [arg("rechunk", long="rechunk", value="true")] +[arg("retry_pull", long="retry-pull", value="true")] [arg("tag", long="tag", short="t")] [group('Image')] -build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false" $kernel_pin="": +build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false" $kernel_pin="" $retry_pull="false": #!/usr/bin/env bash set -eoux pipefail @@ -141,8 +142,10 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false akmods_flavor=$({{ just }} akmods_flavor --tag "${tag}") fedora_version=$({{ just }} fedora_version --image "${image}" --tag "${tag}" --flavor "${flavor}") - # Verify Base Image with cosign - {{ just }} verify-container quay.io-fedora-ostree-desktops.pub ${base_image_org}/${base_image_name}:${fedora_version} + BASE_IMAGE_REF="${base_image_org}/${base_image_name}:${fedora_version}" + ALL_IMAGES=() + {{ just }} verify-container quay.io-fedora-ostree-desktops.pub "${BASE_IMAGE_REF}" + ALL_IMAGES+=("${BASE_IMAGE_REF}") # Here we pin our kernels to workaround regressions! # skopeo list-tags docker://ghcr.io/ublue-os/akmods | jq -r '.Tags | map(select(contains("coreos-stable-44")))' @@ -181,13 +184,22 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false kernel_release="${kernel_pin}" fi - # Verify Containers with Cosign - {{ just }} verify-container cosign.pub "ghcr.io/ublue-os/akmods:${akmods_flavor}-${fedora_version}-${kernel_release}" + BASENAME_AKMODS="ghcr.io/ublue-os/akmods" + + AKMODS="${BASENAME_AKMODS}:${akmods_flavor}-${fedora_version}-${kernel_release}" + {{ just }} verify-container cosign.pub "${AKMODS}" + ALL_IMAGES+=("${AKMODS}") + if [[ "${akmods_flavor}" =~ coreos ]]; then - {{ just }} verify-container cosign.pub "ghcr.io/ublue-os/akmods-zfs:${akmods_flavor}-${fedora_version}-${kernel_release}" + AKMODS_ZFS="${BASENAME_AKMODS}-zfs:${akmods_flavor}-${fedora_version}-${kernel_release}" + {{ just }} verify-container cosign.pub "${AKMODS_ZFS}" + ALL_IMAGES+=("${AKMODS_ZFS}") fi + if [[ "${flavor}" =~ nvidia-open ]]; then - {{ just }} verify-container cosign.pub "ghcr.io/ublue-os/akmods-nvidia-open:${akmods_flavor}-${fedora_version}-${kernel_release}" + AKMODS_NVIDIA_OPEN="${BASENAME_AKMODS}-nvidia-open:${akmods_flavor}-${fedora_version}-${kernel_release}" + {{ just }} verify-container cosign.pub "${AKMODS_NVIDIA_OPEN}" + ALL_IMAGES+=("${AKMODS_NVIDIA_OPEN}") fi cosign verify \ @@ -195,12 +207,27 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false --certificate-identity-regexp="github.com/get-aurora-dev/common/.github/workflows/*" \ "{{ common }}" + ALL_IMAGES+=("{{ common }}") + cosign verify \ --certificate-oidc-issuer https://token.actions.githubusercontent.com \ --certificate-identity-regexp="github.com/coreos/chunkah/.github/workflows/*" \ "{{ chunkah }}" + ALL_IMAGES+=("{{ chunkah }}") + {{ just }} verify-container cosign.pub "{{ brew }}" + ALL_IMAGES+=("{{ brew }}") + + {{ retry_function }} + + # I hate this immensely, podman build/pull with --retry does not work for + # transient network issues + if [[ "${retry_pull}" == "true" ]]; then + for fetch_image in "${ALL_IMAGES[@]}"; do + retry 5 60 ${PODMAN} pull ${fetch_image} + done + fi # Get Version TIMESTAMP="$(date +%Y%m%d)" @@ -270,9 +297,6 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false PODMAN_BUILD_ARGS=("${BUILD_ARGS[@]}" "${LABELS[@]}" --tag "${image_name}:${tag}" --file Containerfile.in) - # Bump retries to minimize network flakes - PODMAN_BUILD_ARGS+=("--retry=5" "--retry-delay=60s") - # So we always have the newest images when building locally if [[ "${ghcr}" == "false" ]]; then PODMAN_BUILD_ARGS+=("--pull=newer") @@ -293,9 +317,10 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false [arg("flavor", long="flavor", short="f")] [arg("image", long="image", short="i")] [arg("kernel_pin", long="kernel-pin")] +[arg("retry_pull", long="retry-pull", value="true")] [arg("tag", long="tag", short="t")] [group('Image')] -build-rechunk $image="aurora" $tag="latest" $flavor="main" kernel_pin="": (build image tag flavor kernel_pin) (rechunk image tag flavor) +build-rechunk $image="aurora" $tag="latest" $flavor="main" $kernel_pin="" $retry_pull="false": (build image tag flavor kernel_pin retry_pull) (rechunk image tag flavor) # Rechunk Image [arg("flavor", long="flavor", short="f")] From 6af2b2781c6eeeebbef18ed3cdf486f36dd876d2 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sat, 4 Jul 2026 23:00:59 +0200 Subject: [PATCH 20/46] feat(ci): package cache with OCI artifacts (#2466) * feat(ci): package cache with OCI artifacts We are hitting a couple limitations in regards to actions/cache [1] with our new testing branch workflow, as we previously relied on scheduled builds from the main branch, which we no longer do with this model. Now we make new cache on merge_group on the first build on Sundays, I chose Sundays just because. Which means we run only a single build with no cache per week and use that same build to generate a new fresh cache. Else we would end up with 3 versions of vscode in our cache. There is no point uploading cache on *every* PR. For simplicity sake this has no handling/differentiation for our stable and main branch. When we bump the fedora version of our main/testing images then the cache for stable will just get stale. We are mixing root/rootless usage of oras/cosign, I made it use root or else we will get premission issues. [1]: https://github.com/actions/cache/issues/1537 fixes: https://github.com/ublue-os/aurora/issues/2351 * define blessed day * chore: remove command -v prefixes not needed, running everything rootless now --- .github/workflows/clean.yml | 8 ++++ .github/workflows/reusable-build.yml | 67 ++++++++++++---------------- Justfile | 46 +++++++++++++++---- 3 files changed, 73 insertions(+), 48 deletions(-) diff --git a/.github/workflows/clean.yml b/.github/workflows/clean.yml index 830c5e8fe..098790b2a 100644 --- a/.github/workflows/clean.yml +++ b/.github/workflows/clean.yml @@ -24,3 +24,11 @@ jobs: delete-orphaned-images: true keep-n-tagged: 7 keep-n-untagged: 7 + + - name: Delete All OCI Artifact Cache + uses: dataaxiom/ghcr-cleanup-action@d52806a0dc70b430571a37da1fde39733ffd640f # v1.2.2 + with: + token: ${{ secrets.GITHUB_TOKEN }} + packages: aurora/cache/dnf + keep-n-tagged: 1 + older-than: 90 days diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index a6d8e409e..7f40f4126 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -91,7 +91,6 @@ jobs: if: inputs.publish - name: Install ORAS - if: inputs.publish uses: oras-project/setup-oras@38de303aac69abb66f3e6255b7198bff35f323e3 # v2.0.0 - name: Check Just Syntax @@ -114,38 +113,23 @@ jobs: echo "IMAGE_NAME=${IMAGE_NAME}" >> $GITHUB_ENV - - name: DNF Package Cache Setup + - name: DNF Package Cache Pull shell: bash - id: setup-cache + id: pull-cache env: MATRIX_BASE_NAME: ${{ matrix.base_name }} MATRIX_STREAM_NAME: ${{ matrix.stream_name }} MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} GITHUB_EVENT_NAME: ${{ github.event_name }} run: | - CACHE="$(just setup-cache \ - --image "${MATRIX_BASE_NAME}" \ - --tag "${MATRIX_STREAM_NAME}" \ - --flavor "${MATRIX_IMAGE_FLAVOR}" \ - --ghcr \ - --github-event "${GITHUB_EVENT_NAME}")" - - CACHE_NAME="$(echo "${CACHE}" | cut -d' ' -f 1)" - ALLOW_CACHE_WRITE="$(echo "${CACHE}" | cut -d' ' -f 2)" - - echo "cache_name=${CACHE_NAME}" >> "$GITHUB_OUTPUT" - echo "allow_cache_write=${ALLOW_CACHE_WRITE}" >> "$GITHUB_OUTPUT" - - - name: Restore DNF package cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - env: - CACHE_NAME: ${{ steps.setup-cache.outputs.cache_name }} - with: - path: /var/tmp/buildah-cache-* - key: ${{ runner.os }}-${{ matrix.architecture }}-buildah-${{ env.CACHE_NAME }}-${{ github.run_id }} - restore-keys: | - ${{ runner.os }}-${{ matrix.architecture }}-buildah-${{ env.CACHE_NAME }}- - ${{ runner.os }}-${{ matrix.architecture }}-buildah-${{ env.CACHE_NAME }} + $(command -v just) \ + setup-cache \ + --image "${MATRIX_BASE_NAME}" \ + --tag "${MATRIX_STREAM_NAME}" \ + --flavor "${MATRIX_IMAGE_FLAVOR}" \ + --ghcr \ + --registry "${IMAGE_REGISTRY}" \ + --pull - name: Build Image id: build-image @@ -165,21 +149,26 @@ jobs: --ghcr \ --retry-pull - # https://github.com/actions/cache/issues/1533 - - name: Hack around permission issue caching - shell: bash - id: cache-perms - run: | - chmod 777 --recursive /var/tmp/buildah-cache-${UID} - - name: Write new DNF package cache - if: steps.setup-cache.outputs.allow_cache_write == 'true' - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + id: push-cache + shell: bash + if: inputs.publish env: - CACHE_NAME: ${{ steps.setup-cache.outputs.cache_name }} - with: - path: /var/tmp/buildah-cache-* - key: ${{ runner.os }}-${{ matrix.architecture }}-buildah-${{ env.CACHE_NAME }}-${{ github.run_id }} + MATRIX_BASE_NAME: ${{ matrix.base_name }} + MATRIX_STREAM_NAME: ${{ matrix.stream_name }} + MATRIX_IMAGE_FLAVOR: ${{ matrix.image_flavor }} + GITHUB_EVENT_NAME: ${{ github.event_name }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + $(command -v just) \ + setup-cache \ + --image "${MATRIX_BASE_NAME}" \ + --tag "${MATRIX_STREAM_NAME}" \ + --flavor "${MATRIX_IMAGE_FLAVOR}" \ + --ghcr \ + --registry "${IMAGE_REGISTRY}" \ + --github-event "${GITHUB_EVENT_NAME}" \ + --push - name: Rechunk Image with Chunkah id: rechunker diff --git a/Justfile b/Justfile index c00875824..9dd99578b 100644 --- a/Justfile +++ b/Justfile @@ -769,15 +769,22 @@ gen-sbom $image="aurora" $tag="latest" $flavor="main" $syft_cmd="syft": rm -rf "${ROOTFS}" +# We are not using https://github.com/actions/cache because of: +# https://github.com/ublue-os/aurora/issues/2351 +# https://github.com/actions/cache/issues/1537 + # DNF CI package cache [arg("flavor", long="flavor", short="f")] [arg("ghcr", long="ghcr", value="true")] [arg("github_event", long="github-event")] [arg("image", long="image", short="i")] +[arg("pull", long="pull", value="true")] +[arg("push", long="push", value="true")] +[arg("registry", long="registry")] [arg("tag", long="tag", short="t")] [group('Utility')] [private] -setup-cache $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $github_event="": +setup-cache $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $pull="false" $push="false" $registry="" $github_event="": #!/usr/bin/env bash set -eou pipefail @@ -785,19 +792,40 @@ setup-cache $image="aurora" $tag="latest" $flavor="main" $ghcr="false" $github_e fedora_version=$({{ just }} fedora_version --image "${image}" --tag "${tag}" --flavor "${flavor}") - ALLOW_CACHE_WRITE="false" - + # compromise between most shared packages BLESSED_IMAGE=aurora-dx - if [[ "${image_name}" == "${BLESSED_IMAGE}" ]] && \ - [[ "${ghcr}" == "true" ]] && \ - [[ "${github_event}" == "workflow_dispatch" || "${github_event}" == "schedule" ]]; then - ALLOW_CACHE_WRITE="true" + CACHE_NAME="aurora/cache/dnf" + CACHE_IMAGE="${registry}/${CACHE_NAME}:${fedora_version}-$(arch)" + + # directory where buildah-cache-UID is + BUILDAH_CACHE_DIR="/var/tmp" + BUILDAH_CACHE="buildah-cache-${UID}" + + POINT=$({{ just }} generate-point --image "${image}" --tag "${tag}" --flavor "${flavor}") + CURRENT_DAY="$(LC_TIME=C date +%A)" + BLESSED_DAY="Sunday" + + if [[ "${CURRENT_DAY}" == "${BLESSED_DAY}" && "$POINT" == "1" && "${ghcr}" == "true" ]]; then + echo "Not pulling build cache. Uploading fresh cache later." + elif [[ "${pull}" == "true" ]]; then + # We want to avoid using --allow-path-traversal + pushd "${BUILDAH_CACHE_DIR}" + oras pull "${CACHE_IMAGE}" || exit 0 + popd fi - CACHE_NAME="${BLESSED_IMAGE}-${fedora_version}" + if [[ "${image_name}" == "${BLESSED_IMAGE}" ]] && \ + [[ "${pull:-false}" == "false" ]] && \ + [[ "${push}" == "true" ]] && \ + [[ "${ghcr}" == "true" ]] && \ + [[ "${github_event}" == "workflow_dispatch" || "${CURRENT_DAY}" == "${BLESSED_DAY}" && "${POINT}" == "1" ]]; then - echo "${CACHE_NAME}" "${ALLOW_CACHE_WRITE}" + {{ just }} login-registry oras ghcr.io + pushd "${BUILDAH_CACHE_DIR}" + oras push "${CACHE_IMAGE}" "${BUILDAH_CACHE}" + popd + fi # Example: just bootc -t testing -- --help [arg("flavor", long="flavor", short="f")] From 573d2c624612e47459a0bab1e219e4aeb1b3ee49 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sun, 5 Jul 2026 03:04:34 +0000 Subject: [PATCH 21/46] chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to 799ee15 (#2509) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 28a0bcb01..e1b526e59 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -15,7 +15,7 @@ images: - name: brew image: ghcr.io/ublue-os/brew tag: latest - digest: sha256:2b3b1e9ede97e191a89325abd1acc9c1b31e0d8d493931e1fdae6e579690ca7c + digest: sha256:799ee1527b95bedbc4b91707e69aeeea0b2425aa5325ae3096865af3174e8035 # https://github.com/coreos/chunkah - name: chunkah From 32a8039b44038132fd76c6daab2a908080a90753 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sun, 5 Jul 2026 04:47:48 +0000 Subject: [PATCH 22/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 92c80b6 (#2510) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index e1b526e59..bb8bc551b 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:59c7dc8dc4d1f9a86e61c3a70e4010598d8d452c533ce380ef5257e60ae05cca + digest: sha256:92c80b6b7ab44c35bb87e7f4451db15465102ff480a047bcc8a3fa8d7ea68ec6 # https://github.com/get-aurora-dev/common - name: common From 12917e012a3d8e1275ba95e84529fb3df46f1917 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Mon, 6 Jul 2026 04:56:53 +0000 Subject: [PATCH 23/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to b85b98e (#2512) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index bb8bc551b..573dd4e64 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:92c80b6b7ab44c35bb87e7f4451db15465102ff480a047bcc8a3fa8d7ea68ec6 + digest: sha256:b85b98e11641d77750294c08e7ba47d18df92548d3f8bd0379135c7bf4771bde # https://github.com/get-aurora-dev/common - name: common From 7a5c941788821c2dc50d08c0da43392f3d1b2a0d Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Mon, 6 Jul 2026 18:38:07 +0000 Subject: [PATCH 24/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to dbcd1f0 (#2515) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 573dd4e64..3e35f6e6b 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:c00fc6bbc6c44d4438f3f93648b8f641e16add723c4b094b854e6460536050b8 + digest: sha256:dbcd1f069bfbbe2bea6a99d025e773fc149d0db5c70ff1721fb3fc62ee124543 # https://github.com/ublue-os/brew - name: brew From a6e3750f5a83c696928cd38d68aac6e1321541d3 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Mon, 6 Jul 2026 20:14:54 +0000 Subject: [PATCH 25/46] chore(deps): update ghcr.io/get-aurora-dev/common:latest docker digest to 3889933 (#2516) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 3e35f6e6b..88d63bc1f 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -9,7 +9,7 @@ images: - name: common image: ghcr.io/get-aurora-dev/common tag: latest - digest: sha256:dbcd1f069bfbbe2bea6a99d025e773fc149d0db5c70ff1721fb3fc62ee124543 + digest: sha256:38899331a8aadb33fe87319bd2483701bcc9b54c0bac868941b76b2e2c4d2127 # https://github.com/ublue-os/brew - name: brew From 1c4a49c4341e10731541bcc01456476e204bb90c Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Tue, 7 Jul 2026 04:46:34 +0000 Subject: [PATCH 26/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 050d2dd (#2518) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 88d63bc1f..dae076888 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:b85b98e11641d77750294c08e7ba47d18df92548d3f8bd0379135c7bf4771bde + digest: sha256:050d2dd8c4588e1e8c762536134289c68b057353430e4ffc084946d74ba49171 # https://github.com/get-aurora-dev/common - name: common From 838bc7895bfd69c2437dbaa72e99cd9aa9ca2bdf Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Wed, 8 Jul 2026 03:46:54 +0000 Subject: [PATCH 27/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 0e3dabc (#2521) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index dae076888..19f8d05c4 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:050d2dd8c4588e1e8c762536134289c68b057353430e4ffc084946d74ba49171 + digest: sha256:0e3dabcb934858d060f07802e61d98260c1b791cba5c9de7afc25e9a2449c075 # https://github.com/get-aurora-dev/common - name: common From e99cd4c7e9ba713b9567f3c60eb50bb0d25f746a Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Wed, 8 Jul 2026 16:25:24 +0300 Subject: [PATCH 28/46] chore(deps): update github/codeql-action digest to 99df26d (main) (#2523) --- .github/workflows/scorecard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 6ab65d69c..520954b6e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -71,6 +71,6 @@ jobs: # Upload the results to GitHub's code scanning dashboard (optional). # Commenting out will disable upload of results to your repo's Code Scanning dashboard - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@54f647b7e1bb85c95cddabcd46b0c578ec92bc1a # v4 + uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4 with: sarif_file: results.sarif From e76ddc06986303123623f7e63bf74a5aa8ad0645 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Wed, 8 Jul 2026 14:54:41 +0000 Subject: [PATCH 29/46] chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to fb4bc94 (#2525) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 19f8d05c4..d9d81bef1 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -15,7 +15,7 @@ images: - name: brew image: ghcr.io/ublue-os/brew tag: latest - digest: sha256:799ee1527b95bedbc4b91707e69aeeea0b2425aa5325ae3096865af3174e8035 + digest: sha256:fb4bc94a46dd6dd0a62f1b09ae2f82acc046288fd5540bf50243cc5e95e5b569 # https://github.com/coreos/chunkah - name: chunkah From 587540823da4127375deeef733faa7c5d991f028 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Wed, 8 Jul 2026 18:40:30 +0200 Subject: [PATCH 30/46] chore(ci): remove build all images workflow (#2527) we haven't used this for over a year, might as well remove it. This used to be needed in a time before we had renovate, before the bluefin split, we build way less images now in general and also latest and stable do not build from the main branch anymore. --- .github/workflows/build-images.yml | 27 --------------------------- 1 file changed, 27 deletions(-) delete mode 100644 .github/workflows/build-images.yml diff --git a/.github/workflows/build-images.yml b/.github/workflows/build-images.yml deleted file mode 100644 index 34a6b361d..000000000 --- a/.github/workflows/build-images.yml +++ /dev/null @@ -1,27 +0,0 @@ -name: Build All Images -on: - workflow_dispatch: - -permissions: - contents: read - packages: write - id-token: write - -jobs: - build-image-stable: - uses: ./.github/workflows/build-image-stable.yml - secrets: inherit - permissions: - contents: write - packages: write - id-token: write - build-image-latest-main: - uses: ./.github/workflows/build-image-latest-main.yml - secrets: inherit - permissions: - contents: write - packages: write - id-token: write -# build-image-beta: -# uses: ./.github/workflows/build-image-beta.yml -# secrets: inherit From 8b90b5809cdb8b74be7a7572feea35daa10da047 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Wed, 8 Jul 2026 19:21:04 +0200 Subject: [PATCH 31/46] chore(ci): tighten image build workflows permissions (#2526) should help a little bit with the openssf score --- .github/workflows/build-image-latest-main.yml | 13 +++++++------ .github/workflows/build-image-stable.yml | 13 +++++++------ .github/workflows/build-image-testing.yml | 13 +++++++------ 3 files changed, 21 insertions(+), 18 deletions(-) diff --git a/.github/workflows/build-image-latest-main.yml b/.github/workflows/build-image-latest-main.yml index 834c62714..2a24f84bd 100644 --- a/.github/workflows/build-image-latest-main.yml +++ b/.github/workflows/build-image-latest-main.yml @@ -20,17 +20,18 @@ on: workflow_call: workflow_dispatch: -permissions: - contents: read - packages: write - id-token: write - attestations: write - artifact-metadata: write +permissions: {} jobs: build-image-latest: name: Build Latest Images uses: ./.github/workflows/reusable-build.yml + permissions: + contents: read + packages: write + id-token: write + attestations: write + artifact-metadata: write secrets: inherit strategy: fail-fast: false diff --git a/.github/workflows/build-image-stable.yml b/.github/workflows/build-image-stable.yml index 19c2e53cd..ab70f5cd3 100644 --- a/.github/workflows/build-image-stable.yml +++ b/.github/workflows/build-image-stable.yml @@ -14,17 +14,18 @@ on: workflow_call: workflow_dispatch: -permissions: - contents: read - packages: write - id-token: write - attestations: write - artifact-metadata: write +permissions: {} jobs: build-image-stable: name: Build Stable Images uses: ./.github/workflows/reusable-build.yml + permissions: + contents: read + packages: write + id-token: write + attestations: write + artifact-metadata: write secrets: inherit strategy: fail-fast: false diff --git a/.github/workflows/build-image-testing.yml b/.github/workflows/build-image-testing.yml index a5ef5e9fe..799a6ebcc 100644 --- a/.github/workflows/build-image-testing.yml +++ b/.github/workflows/build-image-testing.yml @@ -11,17 +11,18 @@ on: workflow_call: workflow_dispatch: -permissions: - contents: read - packages: write - id-token: write - attestations: write - artifact-metadata: write +permissions: {} jobs: build-image-testing: name: Build Testing Images uses: ./.github/workflows/reusable-build.yml + permissions: + contents: read + packages: write + id-token: write + attestations: write + artifact-metadata: write secrets: inherit strategy: fail-fast: false From ba681da966eee74aa1001ae402d029a79879efb5 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Wed, 8 Jul 2026 22:25:29 +0200 Subject: [PATCH 32/46] chore(ci): use built-in release function of gh (#2532) We should not rely on external actions if this functionality exists in official tools. We are only running this step when it's a stable image build so ommiting the make_latest thing is fine to my understanding. xref: https://github.com/ublue-os/aurora/issues/2528 --- .github/workflows/generate-release.yml | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/.github/workflows/generate-release.yml b/.github/workflows/generate-release.yml index 43d1a7185..65df43349 100644 --- a/.github/workflows/generate-release.yml +++ b/.github/workflows/generate-release.yml @@ -59,11 +59,14 @@ jobs: echo "tag=${TAG}" >> $GITHUB_OUTPUT - name: Create Release - uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3 if: contains(fromJson('["stable"]'), matrix.version) && (github.event.schedule == '0 1 * * TUE' || contains(fromJson('["workflow_dispatch", "workflow_call"]'), github.event_name)) - with: - name: ${{ steps.generate-release-text.outputs.title }} - tag_name: ${{ steps.generate-release-text.outputs.tag }} - body_path: ./changelog.md - make_latest: ${{ matrix.version == 'stable' }} - prerelease: false + env: + TITLE: ${{ steps.generate-release-text.outputs.title }} + TAG: ${{ steps.generate-release-text.outputs.tag }} + BODY_PATH: ./changelog.md + run: | + gh release create \ + "${TAG}" \ + --title "${TITLE}" \ + -F "${BODY_PATH}" \ + --latest From 2e7a4111f062dbc785e16e7786b39b085bb43ba9 Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Wed, 8 Jul 2026 22:26:30 +0200 Subject: [PATCH 33/46] chore(ci): mitigate script injection attacks in generate-release (#2531) See: https://docs.github.com/en/actions/concepts/security/script-injections xref: https://github.com/ublue-os/aurora/issues/2528 --- .github/workflows/generate-release.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/generate-release.yml b/.github/workflows/generate-release.yml index 65df43349..cb1a48486 100644 --- a/.github/workflows/generate-release.yml +++ b/.github/workflows/generate-release.yml @@ -51,9 +51,12 @@ jobs: - name: Generate Release Text id: generate-release-text + env: + MATRIX_VERSION: "${{ matrix.version }}" + HANDWRITTEN: "${{ inputs.handwritten }}" shell: bash run: | - just changelogs "${{ matrix.version }}" "${{ inputs.handwritten }}" + just changelogs "${MATRIX_VERSION}" "${HANDWRITTEN}" source ./output.env echo "title=${TITLE}" >> $GITHUB_OUTPUT echo "tag=${TAG}" >> $GITHUB_OUTPUT From 97ad97024fe68312e2c516fc130cd0e3feaab7cc Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Wed, 8 Jul 2026 22:26:59 +0200 Subject: [PATCH 34/46] chore(ci): do not persist credentials in git checkout (#2530) We don't need any credentials after the initial clone. xref: https://github.com/ublue-os/aurora/issues/2528 --- .github/workflows/cherry-pick-to-stable.yml | 1 + .github/workflows/generate-release.yml | 1 + .github/workflows/moderator.yml | 3 +++ .github/workflows/reusable-build.yml | 2 ++ .github/workflows/trigger-schedule-stable-image.yml | 2 ++ .github/workflows/validate-just.yml | 2 ++ .github/workflows/validate-renovate.yml | 2 ++ 7 files changed, 13 insertions(+) diff --git a/.github/workflows/cherry-pick-to-stable.yml b/.github/workflows/cherry-pick-to-stable.yml index 485f20e7b..4453175df 100644 --- a/.github/workflows/cherry-pick-to-stable.yml +++ b/.github/workflows/cherry-pick-to-stable.yml @@ -26,6 +26,7 @@ jobs: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 with: + persist-credentials: false # Use the dynamically generated GitHub App token token: ${{ steps.generate-token.outputs.token }} # Explicitly check out the base branch (the PR is already merged into it). diff --git a/.github/workflows/generate-release.yml b/.github/workflows/generate-release.yml index cb1a48486..89f935811 100644 --- a/.github/workflows/generate-release.yml +++ b/.github/workflows/generate-release.yml @@ -33,6 +33,7 @@ jobs: - name: Checkout last 500 commits (for to work) uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 with: + persist-credentials: false fetch-depth: 500 ref: stable-f44 diff --git a/.github/workflows/moderator.yml b/.github/workflows/moderator.yml index 0d419a41b..7b8876aed 100644 --- a/.github/workflows/moderator.yml +++ b/.github/workflows/moderator.yml @@ -19,6 +19,9 @@ jobs: contents: read steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false + - uses: github/ai-moderator@81159c370785e295c97461ade67d7c33576e9319 # v1 with: token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index 7f40f4126..bea8f320c 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -62,6 +62,8 @@ jobs: steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false # FIXME: We need both actions as we run out of space on /var/tmp, however this # will still fail sometimes as even the smallest 72G runners have a diff --git a/.github/workflows/trigger-schedule-stable-image.yml b/.github/workflows/trigger-schedule-stable-image.yml index f29df9941..9e42ee1b7 100644 --- a/.github/workflows/trigger-schedule-stable-image.yml +++ b/.github/workflows/trigger-schedule-stable-image.yml @@ -16,6 +16,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false - name: Trigger Stable Image Build env: diff --git a/.github/workflows/validate-just.yml b/.github/workflows/validate-just.yml index f8a1563ca..2337aba38 100644 --- a/.github/workflows/validate-just.yml +++ b/.github/workflows/validate-just.yml @@ -20,6 +20,8 @@ jobs: steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false - name: Install Just run: | diff --git a/.github/workflows/validate-renovate.yml b/.github/workflows/validate-renovate.yml index f9f82d657..2892a62d8 100644 --- a/.github/workflows/validate-renovate.yml +++ b/.github/workflows/validate-renovate.yml @@ -20,6 +20,8 @@ jobs: steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 + with: + persist-credentials: false - name: Setup Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 From 1a5d394073b717cc0bb322eda255f188fee207a0 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Thu, 9 Jul 2026 07:14:41 +0200 Subject: [PATCH 35/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 96488d0 (#2534) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index d9d81bef1..46c899c2a 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:0e3dabcb934858d060f07802e61d98260c1b791cba5c9de7afc25e9a2449c075 + digest: sha256:96488d0b604768683d65b3d3b9df85ad947e2400062ae16487811ca130f92083 # https://github.com/get-aurora-dev/common - name: common From d818c4ee09afbd90b75d45df8812abe520680eac Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Thu, 9 Jul 2026 21:07:49 +0200 Subject: [PATCH 36/46] chore(ci): tighten secret usage (#2537) * chore: be explicit about secrets needed for image build Instead of inheriting *all* the secrets we are only selectively giving the called workflows access to the secrets we actually need. Currently we only have one secret we use for image signing but in the future we may want to have a separate testing key we use to sign testing builds only made in PRs and things like that. We may want to look into setting things up in a way so production keys are only ever used when we push to ublue-os/aurora. This also happens to make the experience a little bit nicer in new forks as the workflow will fail right after the start when the SIGNING_SECRET wasn't set, as opposed to when signing the image. xref: https://github.com/ublue-os/aurora/issues/2528 * chore: remove secrets from generate-release parts I don't know why this exists, we don't need our cosign key in this part of the workflow. --- .github/workflows/build-image-latest-main.yml | 4 ++-- .github/workflows/build-image-stable.yml | 4 ++-- .github/workflows/build-image-testing.yml | 3 ++- .github/workflows/reusable-build.yml | 3 +++ 4 files changed, 9 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build-image-latest-main.yml b/.github/workflows/build-image-latest-main.yml index 2a24f84bd..c94bed5ea 100644 --- a/.github/workflows/build-image-latest-main.yml +++ b/.github/workflows/build-image-latest-main.yml @@ -32,7 +32,8 @@ jobs: id-token: write attestations: write artifact-metadata: write - secrets: inherit + secrets: + SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }} strategy: fail-fast: false matrix: @@ -52,7 +53,6 @@ jobs: needs: [build-image-latest] permissions: contents: write - secrets: inherit uses: ./.github/workflows/generate-release.yml with: stream_name: '["latest"]' diff --git a/.github/workflows/build-image-stable.yml b/.github/workflows/build-image-stable.yml index ab70f5cd3..4c05b95bb 100644 --- a/.github/workflows/build-image-stable.yml +++ b/.github/workflows/build-image-stable.yml @@ -26,7 +26,8 @@ jobs: id-token: write attestations: write artifact-metadata: write - secrets: inherit + secrets: + SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }} strategy: fail-fast: false matrix: @@ -44,7 +45,6 @@ jobs: needs: [build-image-stable] permissions: contents: write - secrets: inherit uses: ./.github/workflows/generate-release.yml with: stream_name: '["stable"]' diff --git a/.github/workflows/build-image-testing.yml b/.github/workflows/build-image-testing.yml index 799a6ebcc..7036313d4 100644 --- a/.github/workflows/build-image-testing.yml +++ b/.github/workflows/build-image-testing.yml @@ -23,7 +23,8 @@ jobs: id-token: write attestations: write artifact-metadata: write - secrets: inherit + secrets: + SIGNING_SECRET: ${{ secrets.SIGNING_SECRET }} strategy: fail-fast: false matrix: diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index bea8f320c..321450b98 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -25,6 +25,9 @@ on: required: false type: boolean default: true + secrets: + SIGNING_SECRET: + required: true env: IMAGE_REGISTRY: ghcr.io/${{ github.repository_owner }} From b0b1fc0f507a84c6139d9b779eef01a82edee1f5 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Fri, 10 Jul 2026 09:43:01 +0300 Subject: [PATCH 37/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 2cb7976 (#2539) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 46c899c2a..398d39dbb 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:96488d0b604768683d65b3d3b9df85ad947e2400062ae16487811ca130f92083 + digest: sha256:2cb797635e0472371039036546233f1a31e216153d151ecefb3598a55c830931 # https://github.com/get-aurora-dev/common - name: common From 5659fbcbf51976c611ef2f5d2880ae9362c24806 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sat, 11 Jul 2026 08:29:51 +0300 Subject: [PATCH 38/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 5c83c21 (#2541) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 398d39dbb..2ba17be58 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:2cb797635e0472371039036546233f1a31e216153d151ecefb3598a55c830931 + digest: sha256:5c83c21cc1f3829c8b5b250b383d2a8205baa27b3d5bd6e730a8e3701c789df2 # https://github.com/get-aurora-dev/common - name: common From 4b8993978825f1668b08695cae09c61d27c3b67f Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sat, 11 Jul 2026 21:14:23 +0300 Subject: [PATCH 39/46] chore(deps): update oras-project/setup-oras action to v2.0.1 (#2543) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- .github/workflows/generate-release.yml | 2 +- .github/workflows/reusable-build.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/generate-release.yml b/.github/workflows/generate-release.yml index 89f935811..f3511887d 100644 --- a/.github/workflows/generate-release.yml +++ b/.github/workflows/generate-release.yml @@ -48,7 +48,7 @@ jobs: just check - name: Install ORAS - uses: oras-project/setup-oras@38de303aac69abb66f3e6255b7198bff35f323e3 # v2.0.0 + uses: oras-project/setup-oras@1d808f7d7f6995cc68b7bf507bfe5c5446e1dc9d # v2.0.1 - name: Generate Release Text id: generate-release-text diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index 321450b98..b10f73de7 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -96,7 +96,7 @@ jobs: if: inputs.publish - name: Install ORAS - uses: oras-project/setup-oras@38de303aac69abb66f3e6255b7198bff35f323e3 # v2.0.0 + uses: oras-project/setup-oras@1d808f7d7f6995cc68b7bf507bfe5c5446e1dc9d # v2.0.1 - name: Check Just Syntax shell: bash From d015b6b29b17bd0d16a83382f34b60e739ffcc50 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sun, 12 Jul 2026 09:20:26 +0300 Subject: [PATCH 40/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to a02038e (#2547) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 2ba17be58..e7c0c278f 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:5c83c21cc1f3829c8b5b250b383d2a8205baa27b3d5bd6e730a8e3701c789df2 + digest: sha256:a02038e8b39f7d5a79c72345d1f45b45c96df3730578b2563f43270c4ed0beb8 # https://github.com/get-aurora-dev/common - name: common From adac845823f16cd4c55e63cda504308f8e9eaed3 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Sun, 12 Jul 2026 06:20:58 +0000 Subject: [PATCH 41/46] chore(deps): update ghcr.io/ublue-os/brew:latest docker digest to ff8ac64 (#2546) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index e7c0c278f..6ce9cde24 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -15,7 +15,7 @@ images: - name: brew image: ghcr.io/ublue-os/brew tag: latest - digest: sha256:fb4bc94a46dd6dd0a62f1b09ae2f82acc046288fd5540bf50243cc5e95e5b569 + digest: sha256:ff8ac64d628a0b7f83a4f22484ad65d60a2e732a2cc7174a36330d3cd0b1c7a6 # https://github.com/coreos/chunkah - name: chunkah From ca6ff846ecaf6f18b8a33441747c792c246433de Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Sun, 12 Jul 2026 11:29:59 +0200 Subject: [PATCH 42/46] feat(chunkah): use oci-dir instead of tar-roundtrip (#2545) * feat(chunkah): use oci-dir instead of tar-roundtrip /tmp is a tmpfs backed by RAM (8G) on github so this will also be faster than the current implementation because of that. See: https://github.com/coreos/chunkah#output-options xref: https://github.com/ublue-os/aurora/issues/2350 * always delete config and output dir so we don't fill up /tmp --- Justfile | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/Justfile b/Justfile index 9dd99578b..4fe9f381c 100644 --- a/Justfile +++ b/Justfile @@ -329,23 +329,31 @@ build-rechunk $image="aurora" $tag="latest" $flavor="main" $kernel_pin="" $retry [group('Image')] rechunk $image="aurora" $tag="latest" $flavor="main": #!/usr/bin/env bash + set -eoux pipefail {{ just }} validate --image "${image}" --tag "${tag}" --flavor "${flavor}" image_name=$({{ just }} image_name --image "${image}" --tag "${tag}" --flavor "${flavor}") + CHUNKAH_OUTPUT_DIR="$(mktemp -d)" + CHUNKAH_CONFIG_FILE="$(mktemp)" - export CHUNKAH_CONFIG_STR=$(${PODMAN} inspect "${image_name}:${tag}") - - set -eoux pipefail + trap 'rm -f "${CHUNKAH_CONFIG_FILE}"; rm -rf "${CHUNKAH_OUTPUT_DIR}"' EXIT + ${PODMAN} inspect "${image_name}:${tag}" > "${CHUNKAH_CONFIG_FILE}" ${PODMAN} run --rm --mount=type=image,src="${image_name}:${tag}",target=/chunkah \ - -e CHUNKAH_CONFIG_STR "{{ chunkah }}" \ + -v "${CHUNKAH_CONFIG_FILE}:/chunkah-config.json:ro,Z" \ + -v "${CHUNKAH_OUTPUT_DIR}:/run/out:Z" \ + "{{ chunkah }}" \ build \ --verbose \ --compressed \ --max-layers 128 \ --prune /sysroot/ \ --label ostree.commit- --label ostree.final-diffid- \ - --tag "${image_name}:${tag}" | ${PODMAN} load + --config /chunkah-config.json \ + --output oci:/run/out/chunked + + CHUNKED_IMAGE="$(podman pull "oci:${CHUNKAH_OUTPUT_DIR}/chunked")" + podman tag "${CHUNKED_IMAGE}" "${image_name}:${tag}" # build-chunked-oci [arg("flavor", long="flavor", short="f")] From 7581e8867bbbd7b20e75c580c9f0051a7b0dd8a9 Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Mon, 13 Jul 2026 08:20:19 +0300 Subject: [PATCH 43/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to b46719a (#2550) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 6ce9cde24..40ed2c0a5 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:a02038e8b39f7d5a79c72345d1f45b45c96df3730578b2563f43270c4ed0beb8 + digest: sha256:b46719aad9beb6da5126a264c4ee2fd853ac74250420a473c22d89bec37432b2 # https://github.com/get-aurora-dev/common - name: common From a925e0269feee7c88e8412a1fe79ce0cce3456bc Mon Sep 17 00:00:00 2001 From: renner <80410025+renner0e@users.noreply.github.com> Date: Mon, 13 Jul 2026 16:34:27 +0200 Subject: [PATCH 44/46] feat(ci): setup runner with containers policy (#2549) * feat(ci): setup runner with containers policy Currently for ublue-os/akmods and kinoite (not pinned by digest), we verify them and pull them right after. We can't trust the authenticity of those images, as the tag in the meantime could point to a different, potentially compromised digest. To avoid this, we set up our runner so that it will refuse to pull anything from Universal Blue or quay.io/fedora-ostree-desktops without first getting verified with the corresponding public key in our repo. With this, we can completely get rid of our verify-container recipe and benefit from the retry logic that is implemented in the podman pulls we already do beforehand. This would mean that local builds would no longer verify the pulled images, as the policy is very likely not configured, but I don't think that is super important. * fix: install cosign in non-production builds --- .github/setup-runner-keys.sh | 34 ++++++++++++++++++++++++++++ .github/workflows/reusable-build.yml | 5 +++- Justfile | 32 -------------------------- 3 files changed, 38 insertions(+), 33 deletions(-) create mode 100755 .github/setup-runner-keys.sh diff --git a/.github/setup-runner-keys.sh b/.github/setup-runner-keys.sh new file mode 100755 index 000000000..3843c2a8c --- /dev/null +++ b/.github/setup-runner-keys.sh @@ -0,0 +1,34 @@ +#!/usr/bin/env bash + +# Setup Public Keys for containers that are pulled during the build + +set -eoux pipefail + +PKI_DIR="/etc/pki/containers" +REGISTRIES="/etc/containers/registries.d" + +mkdir -p "${PKI_DIR}" "${REGISTRIES}" +cp cosign.pub "${PKI_DIR}/ghcr.io-ublue-os.pub" +cp quay.io-fedora-ostree-desktops.pub "${PKI_DIR}" + +yq -n '.docker."ghcr.io/ublue-os".use-sigstore-attachments = true' | tee "${REGISTRIES}"/ublue-os.yaml +yq -n '.docker."quay.io/fedora-ostree-desktops".use-sigstore-attachments = true' | tee "${REGISTRIES}"/fedora-ostree-desktops.yaml + +jq '.transports.docker["ghcr.io/ublue-os"] = [ + { + "type": "sigstoreSigned", + "keyPath": "/etc/pki/containers/ghcr.io-ublue-os.pub", + "signedIdentity": { + "type": "matchRepository" + } + } +] | +.transports.docker["quay.io/fedora-ostree-desktops"] = [ + { + "type": "sigstoreSigned", + "keyPath": "/etc/pki/containers/quay.io-fedora-ostree-desktops.pub", + "signedIdentity": { + "type": "matchRepository" + } + } +]' /etc/containers/policy.json | tee /etc/containers/policy.json.tmp > /dev/null && mv /etc/containers/policy.json.tmp /etc/containers/policy.json diff --git a/.github/workflows/reusable-build.yml b/.github/workflows/reusable-build.yml index b10f73de7..d9ec7e36f 100644 --- a/.github/workflows/reusable-build.yml +++ b/.github/workflows/reusable-build.yml @@ -85,6 +85,10 @@ jobs: id: remove-unwanted-software uses: ublue-os/remove-unwanted-software@695eb75bc387dbcd9685a8e72d23439d8686cba6 + - name: Configure containers policy for build + run: | + sudo ./.github/setup-runner-keys.sh + - name: Install Just run: | /home/linuxbrew/.linuxbrew/bin/brew install just @@ -93,7 +97,6 @@ jobs: # FIXME: Implement retries for stuff like this - name: Install Cosign uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 - if: inputs.publish - name: Install ORAS uses: oras-project/setup-oras@1d808f7d7f6995cc68b7bf507bfe5c5446e1dc9d # v2.0.1 diff --git a/Justfile b/Justfile index 4fe9f381c..026991a70 100644 --- a/Justfile +++ b/Justfile @@ -144,7 +144,6 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false BASE_IMAGE_REF="${base_image_org}/${base_image_name}:${fedora_version}" ALL_IMAGES=() - {{ just }} verify-container quay.io-fedora-ostree-desktops.pub "${BASE_IMAGE_REF}" ALL_IMAGES+=("${BASE_IMAGE_REF}") # Here we pin our kernels to workaround regressions! @@ -187,18 +186,15 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false BASENAME_AKMODS="ghcr.io/ublue-os/akmods" AKMODS="${BASENAME_AKMODS}:${akmods_flavor}-${fedora_version}-${kernel_release}" - {{ just }} verify-container cosign.pub "${AKMODS}" ALL_IMAGES+=("${AKMODS}") if [[ "${akmods_flavor}" =~ coreos ]]; then AKMODS_ZFS="${BASENAME_AKMODS}-zfs:${akmods_flavor}-${fedora_version}-${kernel_release}" - {{ just }} verify-container cosign.pub "${AKMODS_ZFS}" ALL_IMAGES+=("${AKMODS_ZFS}") fi if [[ "${flavor}" =~ nvidia-open ]]; then AKMODS_NVIDIA_OPEN="${BASENAME_AKMODS}-nvidia-open:${akmods_flavor}-${fedora_version}-${kernel_release}" - {{ just }} verify-container cosign.pub "${AKMODS_NVIDIA_OPEN}" ALL_IMAGES+=("${AKMODS_NVIDIA_OPEN}") fi @@ -216,7 +212,6 @@ build $image="aurora" $tag="latest" $flavor="main" $rechunk="false" $ghcr="false ALL_IMAGES+=("{{ chunkah }}") - {{ just }} verify-container cosign.pub "{{ brew }}" ALL_IMAGES+=("{{ brew }}") {{ retry_function }} @@ -482,33 +477,6 @@ changelogs branch="stable" handwritten="": set -eou pipefail python3 ./.github/changelogs.py "{{ branch }}" ./output.env ./changelog.md --workdir . --handwritten "{{ handwritten }}" -# Verify Container with Cosign -[group('Utility')] -verify-container key="" container="": - #!/usr/bin/env bash - set -eou pipefail - - # Get Cosign if Needed - if [[ ! $(command -v cosign) ]]; then - COSIGN_CONTAINER_ID=$(${SUDOIF} ${PODMAN} create cgr.dev/chainguard/cosign:latest bash) - ${SUDOIF} ${PODMAN} cp "${COSIGN_CONTAINER_ID}":/usr/bin/cosign /usr/local/bin/cosign - ${SUDOIF} ${PODMAN} rm -f "${COSIGN_CONTAINER_ID}" - fi - - # Verify Cosign Image Signatures if needed - if [[ -n "${COSIGN_CONTAINER_ID:-}" ]]; then - if ! cosign verify --certificate-oidc-issuer=https://token.actions.githubusercontent.com --certificate-identity=https://github.com/chainguard-images/images/.github/workflows/release.yaml@refs/heads/main cgr.dev/chainguard/cosign >/dev/null; then - echo "NOTICE: Failed to verify cosign image signatures." - exit 1 - fi - fi - - # Verify Container using cosign public key - if ! cosign verify --key "{{ key }}" "{{ container }}" >/dev/null; then - echo "NOTICE: Verification failed. Please ensure your public key is correct." - exit 1 - fi - # Secureboot Check [arg("flavor", long="flavor", short="f")] [arg("image", long="image", short="i")] From 74a7581ce59e375a65fd5f49d63022481c5287ea Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Tue, 14 Jul 2026 09:00:38 +0300 Subject: [PATCH 45/46] chore(deps): update quay.io/fedora-ostree-desktops/kinoite:44 docker digest to 70699ca (#2555) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- image-versions.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image-versions.yml b/image-versions.yml index 40ed2c0a5..b1b4b6071 100644 --- a/image-versions.yml +++ b/image-versions.yml @@ -3,7 +3,7 @@ images: - name: kinoite image: quay.io/fedora-ostree-desktops/kinoite tag: 44 - digest: sha256:b46719aad9beb6da5126a264c4ee2fd853ac74250420a473c22d89bec37432b2 + digest: sha256:70699ca22201161ae7727ee5b61a456da2a1c8dff6536c49228558353a92f15e # https://github.com/get-aurora-dev/common - name: common From dc837ebdddbd19f41975eeeaec32a724a33f30cc Mon Sep 17 00:00:00 2001 From: "ubot-7274[bot]" <217212047+ubot-7274[bot]@users.noreply.github.com> Date: Tue, 14 Jul 2026 09:08:40 +0300 Subject: [PATCH 46/46] chore(deps): update actions/setup-node action to v7 (#2556) Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com> --- .github/workflows/validate-renovate.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/validate-renovate.yml b/.github/workflows/validate-renovate.yml index 2892a62d8..c675dfead 100644 --- a/.github/workflows/validate-renovate.yml +++ b/.github/workflows/validate-renovate.yml @@ -24,7 +24,7 @@ jobs: persist-credentials: false - name: Setup Node.js - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: latest