Commit Graph
53 Commits
Author SHA1 Message Date
Tianon Gravi 6c54edada7 Add Windows Server 2025 to allowed external pins 2025-01-17 16:59:11 -08:00
Tianon Gravi 8082a7b36a Adjust "Munge PR" GHA group
The `pull_request_target` event is special, and sets `github.ref` to the _base_ ref, not the PR ref. 🙈
2025-01-10 14:50:38 -08:00
Joseph Ferguson 397df185db Adjust Munge PR action to prevent comment hide/post race
also change group for the test-pr so that they won't conflict
2025-01-07 15:13:12 -08:00
Laurent Goderre 591e15896e Add myself (Laurent) to review more images 2024-12-18 17:02:38 -05:00
Joseph Ferguson ceec25a8e0 Add Laurent as a codeowner to more library files 2024-12-10 14:00:52 -08:00
Laurent Goderre d3d7223bcb Add myself as maintainer of httpd 2024-04-05 13:28:47 -04:00
Tianon Gravi fe8eb602ab Merge pull request #16131 from martin-g/update-github-actions
ci: Update Github actions
2024-03-26 15:17:46 -07:00
Martin Grigorov 3b4f3408f0 ci: Update Github actions
checkout from v3 to v4
github-script from v6 to v7

These fix warnings like:
```
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
```
See https://github.com/docker-library/official-images/actions/runs/7654947388

Signed-off-by: Martin Grigorov <mgrigorov@openeuler.sh>
2024-03-26 22:15:47 +02:00
Tianon Gravi 6a97d7a2e4 Refactor CODEOWNERS, add Laurent explicitly to several things 👀 2024-03-06 16:02:09 -08:00
Tianon Gravi 15f32d18da Update bashbrew to 0.1.12
https://github.com/docker-library/bashbrew/releases/tag/v0.1.12
2024-03-05 11:28:27 -08:00
Tianon Gravi 6fea37fc35 Update bashbrew to 0.1.11
https://github.com/docker-library/bashbrew/releases/tag/v0.1.10
https://github.com/docker-library/bashbrew/releases/tag/v0.1.11
2024-01-22 11:35:46 -08:00
Tianon Gravi 7bca8e6dfe Add new naughty-sharedtags.sh script to detect incorrect SharedTags combinations
Here's an illustration of the problem this catches (the first one we've had with just eyeballing these, so honestly kind of an impressive history):

```console
$ bashbrew list --arch-filter --uniq nats:latest
nats:2.10.8-scratch
nats:2.9.24-scratch
```

Example output:

```console
$ ./naughty-sharedtags.sh
 - nats:2, nats:latest: (duplicate architectures in SharedTags; nats:2.10.8-scratch, nats:2.10.8-nanoserver-1809, nats:2.9.24-scratch)
   - amd64
   - amd64
   - arm32v6
   - arm32v6
   - arm32v7
   - arm32v7
   - arm64v8
   - arm64v8
```
2024-01-11 15:48:53 -08:00
Tianon Gravi b7abf65524 Add initial GitHub CODEOWNERS 2024-01-03 11:27:21 -08:00
Joseph Ferguson 5f5a73def4 Update bashbrew action to 0.1.9
this release disables cgo during the bashbrew.sh build script which will fix the `windows-2022` build failures on GitHub actions

> C:\hostedtoolcache\windows\go\1.18.10\x64\pkg\tool\windows_amd64\link.exe: running gcc failed: exit status 1
2023-10-25 13:27:40 -07:00
Tianon Gravi b3ed7e9f91 Validate all naughty even in the face of one naughty 2023-02-21 15:13:32 -08:00
Tianon Gravi 6a530d68a8 Hide diff comments instead of deleting them 2023-02-17 15:52:07 -08:00
Tianon Gravi 79a269637f Add support for "Builder: oci-import" in diff-pr
Also, update other scripts to use `bashbrew fetch` and `gitCache` effectively to remove unnecessary reimplementations of `BASHBREW_CACHE` default value calculation (new in bashbrew v0.1.8).

As a parting gift, add the raw list of total supported architectures to a file so it's more obvious when new ones are added or removed (like `ubuntu` losing `riscv64`).
2023-02-15 13:22:05 -08:00
Tianon Gravi cdc2c8a989 Add support for "external pins" in "diff-pr.sh"
This uses `crane` to download some of the JSON files of the remote images to give us at least *some* amount of diffing between updates to external pins.
2023-01-13 14:38:54 -08:00
Tianon Gravi da1f21f76d Update to bashbrew 0.1.7
Notably, this adds support for `Builder: oci-import`
2022-12-19 11:14:50 -08:00
Tianon Gravi c18b650ec9 Add explicit "external-pins", take two
This is a second attempt at 98575e0538:

> The goal of this directory is two-fold: to list the explicitly allowable external dependencies and to pin those external dependencies to a specific content-addressable digest such that we can update them in the same way we do everything else (and then trigger rebuilds properly based on them, too).

See `.external-pins/list.sh` for a useful summary of the assumptions that went into the naming scheme.
2022-11-29 14:08:16 -08:00
Tianon Gravi f5a4e454a7 Revert "Add explicit "external-pins"" 2022-11-29 11:49:47 -08:00
Tianon Gravi 98575e0538 Add explicit "external-pins"
The goal of this directory is two-fold: to list the explicitly allowable external dependencies and to pin those external dependencies to a specific content-addressable digest such that we can update them in the same way we do everything else (and then trigger rebuilds properly based on them, too).
2022-11-18 17:46:38 -08:00
Tianon Gravi 440ac1aabd Update bashbrew to 0.1.5 (and use the new bashbrew action) 2022-11-17 15:31:30 -08:00
Tianon Gravi 602cc65097 Update more "bashbrew.git" references in the repo to use "bashbrew-version" 2022-10-24 15:58:58 -07:00
Tianon Gravi a59abe2fb9 Remove BASHBREW_GENERATE_SKIP_PGP_PROXY (no longer used) 2022-06-27 15:13:05 -07:00
naveen 24fba907a8 chore: Set permissions for GitHub actions
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
2022-06-12 00:31:16 +00:00
Tianon Gravi 4faa4579ff Write PR diff to GITHUB_STEP_SUMMARY 2022-05-10 12:15:44 -07:00
Joe Ferguson 02e57c3af3 Skip pgp-happy-eyeballs on build tests
https://github.com/docker-library/official-images/pull/11917#issuecomment-1049236174
2022-02-23 16:15:40 -08:00
Rob Cowsill d0c35646ec Turn trace off during workflow commands
Required so the resume token isn't leaked in the logs, and to
prevent any interference with workflow command processing
2021-11-26 15:23:45 +00:00
Rob Cowsill 16ef34a23a Prevent code injection
* Stop workflow command processing until the set-output command
* Parse JSON instead of injecting it into the source
* Restrict permissions to minimum required
2021-11-25 16:14:47 +00:00
Tianon Gravi 6b701d8410 Fix comments pagination in "Munge PR" 2021-10-20 16:58:20 -07:00
Tianon Gravi 6b31fa06e3 Merge pull request #10879 from infosiftr/test-better-munge
Make "Munge PR" more intelligent (test PR)
2021-10-11 16:35:26 +00:00
George Adams ab4eed6c03 actions: auto cancel builds if user pushes another commit (#10991) 2021-09-30 14:31:39 -07:00
Tianon Gravi f0edc7c298 Make "Munge PR" more intelligent 2021-09-09 16:00:57 -07:00
Tianon Gravi 7449616ec1 Update "munge-pr.yml" to run "diff-pr.sh" inside a container
This avoids accidentally reintroducing CVE-2020-15228 (for example, having a PR that changes `diff-pr.sh` to write something malicious to `$GITHUB_ENV`).
2020-11-30 17:05:58 -08:00
Tianon Gravi cf7abb9b67 Stage the PR diff in a file instead of a variable (avoiding length limits) 2020-11-17 01:27:26 -08:00
Tianon Gravi 6e417c94f7 Pass along the PR diff via environment variable instead of outputs 2020-11-17 00:28:43 -08:00
Tianon Gravi 254a5aee42 Fix typo 2020-11-16 17:23:06 -08:00
Tianon Gravi 752c8cde54 Switch from external script to embedded to fix branch drift 2020-11-16 16:38:48 -08:00
Tianon Gravi c2def78393 Add workaround for "merge_commit_sha" not being set quickly enough...
See https://docs.github.com/en/free-pro-team@latest/rest/reference/pulls#get-a-pull-request (and/or https://github.community/t/why-does-merge-commit-sha-change-during-action-run/129932/2?u=tianon)
2020-11-16 11:22:56 -08:00
Tianon Gravi 693326e3f2 Add new "Munge PR" workflow using "pull_request_target" 2020-11-16 10:00:20 -08:00
Tianon Gravi cb58d204f3 Update test-pr action from set-env to $GITHUB_ENV file
See https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/
2020-10-06 16:37:42 -07:00
Tianon Gravi af378d70ca Set "GIT_LFS_SKIP_SMUDGE" in both GitHub Actions to prevent LFS from breaking diff/test
See https://github.com/docker-library/bashbrew/issues/10 for details and https://github.com/docker-library/official-images/pull/8282 for the PR which failed and caused us to notice. 😅
2020-06-30 12:25:14 -07:00
Tianon Gravi eef6790f39 Update Github Actions to use our local clone for running tests
This allows test changes to be tested too, if they live in the PR with the image change.
2020-05-15 13:56:58 -07:00
Tianon Gravi c50488efd5 Fix generate for really long matrices 2020-05-07 13:05:46 -07:00
Tianon Gravi 3e21779c20 Adjust "actions/checkout@v2" params to unshallow so that we can properly detect which files changed in the PR 2020-05-06 13:47:26 -07:00
Tianon Gravi d6816f0a19 Add "initial diffing" commit URL 2020-05-05 16:29:36 -07:00
Tianon Gravi 088d51bfde Move PR diff generation to our separate "Periodic" workflow 2020-05-05 16:28:58 -07:00
Tianon Gravi dc9cd282e7 Rename workflow job to "Periodic Actions" 2020-05-05 16:24:56 -07:00
Tianon Gravi 07c8f39371 Remove unnecessary actions/checkout in PR labeller job 2020-05-05 15:12:49 -07:00