Tianon Gravi
6c54edada7
Add Windows Server 2025 to allowed external pins
2025-01-17 16:59:11 -08:00
Tianon Gravi
8082a7b36a
Adjust "Munge PR" GHA group
...
The `pull_request_target` event is special, and sets `github.ref` to the _base_ ref, not the PR ref. 🙈
2025-01-10 14:50:38 -08:00
Joseph Ferguson
397df185db
Adjust Munge PR action to prevent comment hide/post race
...
also change group for the test-pr so that they won't conflict
2025-01-07 15:13:12 -08:00
Laurent Goderre
591e15896e
Add myself (Laurent) to review more images
2024-12-18 17:02:38 -05:00
Joseph Ferguson
ceec25a8e0
Add Laurent as a codeowner to more library files
2024-12-10 14:00:52 -08:00
Laurent Goderre
d3d7223bcb
Add myself as maintainer of httpd
2024-04-05 13:28:47 -04:00
Tianon Gravi
fe8eb602ab
Merge pull request #16131 from martin-g/update-github-actions
...
ci: Update Github actions
2024-03-26 15:17:46 -07:00
Martin Grigorov
3b4f3408f0
ci: Update Github actions
...
checkout from v3 to v4
github-script from v6 to v7
These fix warnings like:
```
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/ .
```
See https://github.com/docker-library/official-images/actions/runs/7654947388
Signed-off-by: Martin Grigorov <mgrigorov@openeuler.sh >
2024-03-26 22:15:47 +02:00
Tianon Gravi
6a97d7a2e4
Refactor CODEOWNERS, add Laurent explicitly to several things 👀
2024-03-06 16:02:09 -08:00
Tianon Gravi
15f32d18da
Update bashbrew to 0.1.12
...
https://github.com/docker-library/bashbrew/releases/tag/v0.1.12
2024-03-05 11:28:27 -08:00
Tianon Gravi
6fea37fc35
Update bashbrew to 0.1.11
...
https://github.com/docker-library/bashbrew/releases/tag/v0.1.10
https://github.com/docker-library/bashbrew/releases/tag/v0.1.11
2024-01-22 11:35:46 -08:00
Tianon Gravi
7bca8e6dfe
Add new naughty-sharedtags.sh script to detect incorrect SharedTags combinations
...
Here's an illustration of the problem this catches (the first one we've had with just eyeballing these, so honestly kind of an impressive history):
```console
$ bashbrew list --arch-filter --uniq nats:latest
nats:2.10.8-scratch
nats:2.9.24-scratch
```
Example output:
```console
$ ./naughty-sharedtags.sh
- nats:2, nats:latest: (duplicate architectures in SharedTags; nats:2.10.8-scratch, nats:2.10.8-nanoserver-1809, nats:2.9.24-scratch)
- amd64
- amd64
- arm32v6
- arm32v6
- arm32v7
- arm32v7
- arm64v8
- arm64v8
```
2024-01-11 15:48:53 -08:00
Tianon Gravi
b7abf65524
Add initial GitHub CODEOWNERS
2024-01-03 11:27:21 -08:00
Joseph Ferguson
5f5a73def4
Update bashbrew action to 0.1.9
...
this release disables cgo during the bashbrew.sh build script which will fix the `windows-2022` build failures on GitHub actions
> C:\hostedtoolcache\windows\go\1.18.10\x64\pkg\tool\windows_amd64\link.exe: running gcc failed: exit status 1
2023-10-25 13:27:40 -07:00
Tianon Gravi
b3ed7e9f91
Validate all naughty even in the face of one naughty
2023-02-21 15:13:32 -08:00
Tianon Gravi
6a530d68a8
Hide diff comments instead of deleting them
2023-02-17 15:52:07 -08:00
Tianon Gravi
79a269637f
Add support for "Builder: oci-import" in diff-pr
...
Also, update other scripts to use `bashbrew fetch` and `gitCache` effectively to remove unnecessary reimplementations of `BASHBREW_CACHE` default value calculation (new in bashbrew v0.1.8).
As a parting gift, add the raw list of total supported architectures to a file so it's more obvious when new ones are added or removed (like `ubuntu` losing `riscv64`).
2023-02-15 13:22:05 -08:00
Tianon Gravi
cdc2c8a989
Add support for "external pins" in "diff-pr.sh"
...
This uses `crane` to download some of the JSON files of the remote images to give us at least *some* amount of diffing between updates to external pins.
2023-01-13 14:38:54 -08:00
Tianon Gravi
da1f21f76d
Update to bashbrew 0.1.7
...
Notably, this adds support for `Builder: oci-import`
2022-12-19 11:14:50 -08:00
Tianon Gravi
c18b650ec9
Add explicit "external-pins", take two
...
This is a second attempt at 98575e0538 :
> The goal of this directory is two-fold: to list the explicitly allowable external dependencies and to pin those external dependencies to a specific content-addressable digest such that we can update them in the same way we do everything else (and then trigger rebuilds properly based on them, too).
See `.external-pins/list.sh` for a useful summary of the assumptions that went into the naming scheme.
2022-11-29 14:08:16 -08:00
Tianon Gravi
f5a4e454a7
Revert "Add explicit "external-pins""
2022-11-29 11:49:47 -08:00
Tianon Gravi
98575e0538
Add explicit "external-pins"
...
The goal of this directory is two-fold: to list the explicitly allowable external dependencies and to pin those external dependencies to a specific content-addressable digest such that we can update them in the same way we do everything else (and then trigger rebuilds properly based on them, too).
2022-11-18 17:46:38 -08:00
Tianon Gravi
440ac1aabd
Update bashbrew to 0.1.5 (and use the new bashbrew action)
2022-11-17 15:31:30 -08:00
Tianon Gravi
602cc65097
Update more "bashbrew.git" references in the repo to use "bashbrew-version"
2022-10-24 15:58:58 -07:00
Tianon Gravi
a59abe2fb9
Remove BASHBREW_GENERATE_SKIP_PGP_PROXY (no longer used)
2022-06-27 15:13:05 -07:00
naveen
24fba907a8
chore: Set permissions for GitHub actions
...
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ )
Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com >
2022-06-12 00:31:16 +00:00
Tianon Gravi
4faa4579ff
Write PR diff to GITHUB_STEP_SUMMARY
2022-05-10 12:15:44 -07:00
Joe Ferguson
02e57c3af3
Skip pgp-happy-eyeballs on build tests
...
https://github.com/docker-library/official-images/pull/11917#issuecomment-1049236174
2022-02-23 16:15:40 -08:00
Rob Cowsill
d0c35646ec
Turn trace off during workflow commands
...
Required so the resume token isn't leaked in the logs, and to
prevent any interference with workflow command processing
2021-11-26 15:23:45 +00:00
Rob Cowsill
16ef34a23a
Prevent code injection
...
* Stop workflow command processing until the set-output command
* Parse JSON instead of injecting it into the source
* Restrict permissions to minimum required
2021-11-25 16:14:47 +00:00
Tianon Gravi
6b701d8410
Fix comments pagination in "Munge PR"
2021-10-20 16:58:20 -07:00
Tianon Gravi
6b31fa06e3
Merge pull request #10879 from infosiftr/test-better-munge
...
Make "Munge PR" more intelligent (test PR)
2021-10-11 16:35:26 +00:00
George Adams
ab4eed6c03
actions: auto cancel builds if user pushes another commit ( #10991 )
2021-09-30 14:31:39 -07:00
Tianon Gravi
f0edc7c298
Make "Munge PR" more intelligent
2021-09-09 16:00:57 -07:00
Tianon Gravi
7449616ec1
Update "munge-pr.yml" to run "diff-pr.sh" inside a container
...
This avoids accidentally reintroducing CVE-2020-15228 (for example, having a PR that changes `diff-pr.sh` to write something malicious to `$GITHUB_ENV`).
2020-11-30 17:05:58 -08:00
Tianon Gravi
cf7abb9b67
Stage the PR diff in a file instead of a variable (avoiding length limits)
2020-11-17 01:27:26 -08:00
Tianon Gravi
6e417c94f7
Pass along the PR diff via environment variable instead of outputs
2020-11-17 00:28:43 -08:00
Tianon Gravi
254a5aee42
Fix typo
2020-11-16 17:23:06 -08:00
Tianon Gravi
752c8cde54
Switch from external script to embedded to fix branch drift
2020-11-16 16:38:48 -08:00
Tianon Gravi
c2def78393
Add workaround for "merge_commit_sha" not being set quickly enough...
...
See https://docs.github.com/en/free-pro-team@latest/rest/reference/pulls#get-a-pull-request (and/or https://github.community/t/why-does-merge-commit-sha-change-during-action-run/129932/2?u=tianon )
2020-11-16 11:22:56 -08:00
Tianon Gravi
693326e3f2
Add new "Munge PR" workflow using "pull_request_target"
2020-11-16 10:00:20 -08:00
Tianon Gravi
cb58d204f3
Update test-pr action from set-env to $GITHUB_ENV file
...
See https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/
2020-10-06 16:37:42 -07:00
Tianon Gravi
af378d70ca
Set "GIT_LFS_SKIP_SMUDGE" in both GitHub Actions to prevent LFS from breaking diff/test
...
See https://github.com/docker-library/bashbrew/issues/10 for details and https://github.com/docker-library/official-images/pull/8282 for the PR which failed and caused us to notice. 😅
2020-06-30 12:25:14 -07:00
Tianon Gravi
eef6790f39
Update Github Actions to use our local clone for running tests
...
This allows test changes to be tested too, if they live in the PR with the image change.
2020-05-15 13:56:58 -07:00
Tianon Gravi
c50488efd5
Fix generate for really long matrices
2020-05-07 13:05:46 -07:00
Tianon Gravi
3e21779c20
Adjust "actions/checkout@v2" params to unshallow so that we can properly detect which files changed in the PR
2020-05-06 13:47:26 -07:00
Tianon Gravi
d6816f0a19
Add "initial diffing" commit URL
2020-05-05 16:29:36 -07:00
Tianon Gravi
088d51bfde
Move PR diff generation to our separate "Periodic" workflow
2020-05-05 16:28:58 -07:00
Tianon Gravi
dc9cd282e7
Rename workflow job to "Periodic Actions"
2020-05-05 16:24:56 -07:00
Tianon Gravi
07c8f39371
Remove unnecessary actions/checkout in PR labeller job
2020-05-05 15:12:49 -07:00