Skip to content

refactor(mcp): rename + repurpose MCP tools for social-media scope #44

refactor(mcp): rename + repurpose MCP tools for social-media scope

refactor(mcp): rename + repurpose MCP tools for social-media scope #44

Workflow file for this run

name: publish
on:
push:
tags:
- 'v*'
workflow_dispatch:
permissions:
contents: read
packages: write
env:
REGISTRY: ghcr.io
# GHCR normalizes package paths to lowercase — the GitHub repo name
# `Fectivnfy112357/camofox-opencli` would otherwise be rejected by
# buildx with "repository name must be lowercase". GitHub Actions
# expression parser doesn't allow `|` filters inside multi-line
# `tags:` strings, so the lowercase owner is hard-coded here. Update
# this when transferring the repo.
IMAGE_OWNER: fectivnfy112357
IMAGE_NAME: camofox-opencli
jobs:
build:
runs-on: ubuntu-latest
# Required for first-time push to ghcr.io/fectivnfy112357/camofox-opencli
# — without packages:write, GHCR rejects the push with
# "denied: permission_denied: The token provided does not match
# expected scopes." even when the repo's default workflow
# permission is set to "write".
permissions:
contents: read
packages: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '24'
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GHCR
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
# Use the auto-issued GITHUB_TOKEN — the repo's default
# workflow permission is set to "write" via the REST API
# (default_workflow_permissions: write), which grants
# packages:write for first-time package creation on GHCR.
password: ${{ secrets.GITHUB_TOKEN }}
- name: Clone camofox-browser
run: |
git clone --depth 1 https://github.com/Fectivnfy112357/camofox-browser.git camofox-browser
- name: Clone opencli
run: |
git clone --depth 1 https://github.com/Fectivnfy112357/opencli.git opencli
- name: Extract version metadata
id: meta
run: |
if [[ "${GITHUB_REF_TYPE}" == "tag" ]]; then
VERSION=${GITHUB_REF_NAME}
else
VERSION=$(date +%Y%m%d-%H%M%S)
fi
SHORT_SHA=$(echo "${GITHUB_SHA}" | cut -c1-7)
echo "VERSION=${VERSION}" >> $GITHUB_OUTPUT
echo "SHORT_SHA=${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
file: Dockerfile.publish
# The sibling sources cloned above are referenced by the
# Dockerfile via `COPY --from=camofox-browser` / `COPY --from=opencli`.
# BuildKit treats these names as BuildKit named contexts (NOT
# Docker images), so they resolve to local directories here.
build-contexts: |
camofox-browser=${{ github.workspace }}/camofox-browser
opencli=${{ github.workspace }}/opencli
push: ${{ github.event_name != 'pull_request' }}
tags: |
${{ env.REGISTRY }}/${{ env.IMAGE_OWNER }}/${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.VERSION }}
${{ env.REGISTRY }}/${{ env.IMAGE_OWNER }}/${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.SHORT_SHA }}
${{ env.REGISTRY }}/${{ env.IMAGE_OWNER }}/${{ env.IMAGE_NAME }}:latest
labels: |
org.opencontainers.image.title=camofox-opencli
org.opencontainers.image.description=Cloud OpenCLI with anti-detection Camofox browser + 163+ site adapters + MCP gateway
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.revision=${{ github.sha }}
org.opencontainers.image.version=${{ steps.meta.outputs.VERSION }}
cache-from: type=gha
cache-to: type=gha,mode=max
build-args: |
CAMOUFOX_TAG=v152.0.4-beta.28
platforms: linux/amd64