comments, second pass

This commit is contained in:
tooomm 2026-08-21 22:35:39 +02:00 • committed by GitHub
parent 0a9da50b44
commit 72c384450a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -2,7 +2,6 @@ name: Build Docker
permissions: permissions:
contents: read # needed to checkout repo contents: read # needed to checkout repo
id-token: write # needed for signing attestations (SBOM & provenance) with GitHub OIDC
packages: write # needed for interacting with GHCR packages: write # needed for interacting with GHCR
on: on:
@ -105,7 +104,7 @@ jobs:
env: env:
DIGEST: ${{ steps.build.outputs.digest }} DIGEST: ${{ steps.build.outputs.digest }}
run: | run: |
mkdir -p $RUNNER_TEMP/digests mkdir -p "$RUNNER_TEMP/digests"
touch "$RUNNER_TEMP/digests/${DIGEST#sha256:}" touch "$RUNNER_TEMP/digests/${DIGEST#sha256:}"
- name: "Upload digest" - name: "Upload digest"
@ -129,6 +128,7 @@ jobs:
- name: "Download digests" - name: "Download digests"
uses: actions/download-artifact@v7 uses: actions/download-artifact@v7
with: with:
if_no_artifact_found: fail
path: ${{ runner.temp }}/digests path: ${{ runner.temp }}/digests
pattern: digest-* pattern: digest-*
merge-multiple: true merge-multiple: true
@ -154,12 +154,16 @@ jobs:
- name: "Create image index" - name: "Create image index"
env: env:
DOCKER_TAGS: ${{ steps.metadata.outputs.tags }} DOCKER_TAGS: ${{ steps.metadata.outputs.tags }}
GITHUB_TAG: ${{ github.ref_name }}
working-directory: ${{ runner.temp }}/digests working-directory: ${{ runner.temp }}/digests
run: | run: |
TAG_ARGS="" TAG_ARGS=()
for tag in $DOCKER_TAGS; do while IFS= read -r tag; do
TAG_ARGS="$TAG_ARGS --tag $tag" TAG_ARGS+=(--tag "$tag")
done <<< "$DOCKER_TAGS"
DIGEST_ARGS=()
for digest in *; do
DIGEST_ARGS+=("$GHCR_IMAGE@sha256:$digest")
done done
docker buildx imagetools create \ docker buildx imagetools create \
@ -167,10 +171,12 @@ jobs:
--annotation "index:org.opencontainers.image.description=$OCI_DESCRIPTION" \ --annotation "index:org.opencontainers.image.description=$OCI_DESCRIPTION" \
--annotation "index:org.opencontainers.image.title=$OCI_TITLE" \ --annotation "index:org.opencontainers.image.title=$OCI_TITLE" \
--annotation "index:org.opencontainers.image.url=$OCI_URL" \ --annotation "index:org.opencontainers.image.url=$OCI_URL" \
$TAG_ARGS \ "${TAG_ARGS[@]}" \
$(printf "$GHCR_IMAGE@sha256:%s " *) "${DIGEST_ARGS[@]}"
- name: "Inspect images" - name: "Inspect images"
env:
GITHUB_TAG: ${{ github.ref_name }}
run: | run: |
docker buildx imagetools inspect "$GHCR_IMAGE:latest" docker buildx imagetools inspect "$GHCR_IMAGE:latest"
docker buildx imagetools inspect "$GHCR_IMAGE:$GITHUB_TAG" docker buildx imagetools inspect "$GHCR_IMAGE:$GITHUB_TAG"