-
Notifications
You must be signed in to change notification settings - Fork 16
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #17 from bcgov/chore/security
Update Python base image to 3.12-alpine
- Loading branch information
Showing
7 changed files
with
160 additions
and
18 deletions.
There are no files selected for viewing
Validating CODEOWNERS rules …
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
# These users will be the default owners for everything in the repo. | ||
# Unless a later match takes precedence, the following users will be | ||
# requested for review when someone opens a pull request. | ||
@kyle1morel @TimCsaky @wilwong89 @jatindersingh93 @norrisng-bc |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,87 @@ | ||
name: Build & Push Container | ||
description: Builds a container from a Dockerfile and pushes to registry | ||
|
||
inputs: | ||
context: | ||
description: Effective Working Directory | ||
required: true | ||
default: "./" | ||
image_name: | ||
description: Image Name | ||
required: true | ||
github_username: | ||
description: Github Container Registry Username | ||
required: true | ||
github_token: | ||
description: Github Container Registry Authorization Token | ||
required: true | ||
dockerhub_username: | ||
description: Dockerhub Container Registry Username | ||
required: false | ||
dockerhub_organization: | ||
description: Dockerhub Container Registry Organization | ||
required: false | ||
default: bcgovimages | ||
dockerhub_token: | ||
description: Dockerhub Container Registry Authorization Token | ||
required: false | ||
|
||
runs: | ||
using: composite | ||
steps: | ||
- name: Checkout repository | ||
uses: actions/checkout@v4 | ||
|
||
- name: Parse Input Values | ||
shell: bash | ||
run: | | ||
echo "GH_USERNAME=$(tr '[:upper:]' '[:lower:]' <<< '${{ inputs.github_username }}')" >> $GITHUB_ENV | ||
echo "HAS_DOCKERHUB=${{ fromJson(inputs.dockerhub_username != '' && inputs.dockerhub_token != '') }}" >> $GITHUB_ENV | ||
- name: Login to Github Container Registry | ||
uses: docker/login-action@v3 | ||
with: | ||
registry: ghcr.io | ||
username: ${{ env.GH_USERNAME }} | ||
password: ${{ inputs.github_token }} | ||
|
||
- name: Login to Dockerhub Container Registry | ||
if: env.HAS_DOCKERHUB == 'true' | ||
uses: docker/login-action@v3 | ||
with: | ||
registry: docker.io | ||
username: ${{ inputs.dockerhub_username }} | ||
password: ${{ inputs.dockerhub_token }} | ||
|
||
- name: Prepare Container Metadata tags | ||
id: meta | ||
uses: docker/metadata-action@v5 | ||
with: | ||
images: | | ||
ghcr.io/${{ env.GH_USERNAME }}/${{ inputs.image_name }} | ||
docker.io/${{ inputs.dockerhub_organization }}/${{ inputs.image_name }},enable=${{ env.HAS_DOCKERHUB }} | ||
# Always updates the 'latest' tag | ||
flavor: | | ||
latest=true | ||
# Creates tags based off of branch names and semver tags | ||
tags: | | ||
type=ref,event=branch | ||
type=ref,event=pr | ||
type=semver,pattern={{version}} | ||
type=semver,pattern={{major}}.{{minor}} | ||
type=semver,pattern={{major}} | ||
type=sha | ||
- name: Build and Push to Container Registry | ||
id: builder | ||
uses: docker/build-push-action@v5 | ||
with: | ||
context: ${{ inputs.context }} | ||
push: true | ||
tags: ${{ steps.meta.outputs.tags }} | ||
labels: ${{ steps.meta.outputs.labels }} | ||
|
||
- name: Inspect Docker Image | ||
shell: bash | ||
run: | | ||
docker image inspect ghcr.io/${{ env.GH_USERNAME }}/${{ inputs.image_name }}:latest |
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,34 @@ | ||
name: Pull Request Opened | ||
|
||
env: | ||
APP_NAME: clamav-mirror | ||
|
||
on: | ||
pull_request: | ||
branches: | ||
- master | ||
types: | ||
- opened | ||
- reopened | ||
- synchronize | ||
|
||
concurrency: | ||
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | ||
cancel-in-progress: true | ||
|
||
jobs: | ||
build: | ||
name: Build & Push | ||
if: "! github.event.pull_request.head.repo.fork" | ||
runs-on: ubuntu-latest | ||
timeout-minutes: 10 | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
- name: Build & Push | ||
uses: ./.github/actions/build-push-container | ||
with: | ||
context: ./docker | ||
image_name: ${{ env.APP_NAME }} | ||
github_username: ${{ github.repository_owner }} | ||
github_token: ${{ secrets.GITHUB_TOKEN }} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
name: Push | ||
|
||
env: | ||
APP_NAME: clamav-mirror | ||
|
||
on: | ||
push: | ||
branches: | ||
- master | ||
tags: | ||
- v*.*.* | ||
|
||
concurrency: | ||
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | ||
cancel-in-progress: true | ||
|
||
jobs: | ||
build: | ||
name: Build & Push | ||
runs-on: ubuntu-latest | ||
timeout-minutes: 10 | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
- name: Build & Push | ||
uses: ./.github/actions/build-push-container | ||
with: | ||
context: ./docker | ||
image_name: ${{ env.APP_NAME }} | ||
github_username: ${{ github.repository_owner }} | ||
github_token: ${{ secrets.GITHUB_TOKEN }} | ||
dockerhub_username: ${{ secrets.DOCKERHUB_USERNAME }} | ||
dockerhub_token: ${{ secrets.DOCKERHUB_TOKEN }} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters