-
Notifications
You must be signed in to change notification settings - Fork 0
143 lines (121 loc) · 3.84 KB
/
Copy pathrelease.yaml
File metadata and controls
143 lines (121 loc) · 3.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
---
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
name: Release
on:
push:
tags:
- 'v*'
permissions:
contents: read
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: true
jobs:
create-draft-release:
name: Create draft release
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Draft Release
run: |
gh release create "${GITHUB_REF_NAME}" \
--title "Release ${GITHUB_REF_NAME}" \
--notes "Full Changelog: https://github.com/${{ github.repository }}/commits/${{ github.ref_name }}" \
--draft
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
build-and-publish:
name: Build, Push & Sign
needs: create-draft-release
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write
outputs:
image_digest: ${{ steps.build.outputs.digest }}
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Cosign
uses: sigstore/cosign-installer@v4.1.0
- name: Install Trivy
uses: aquasecurity/setup-trivy@v0.2.5
- name: Log in to Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
with:
platforms: amd64,arm64
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and Push
id: build
uses: docker/build-push-action@v6
with:
context: .
push: true
platforms: linux/amd64,linux/arm64
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-to: type=gha,mode=max
cache-from: type=gha
build-args: |
BUILDKIT_INLINE_CACHE=1
- name: Sign image
run: |
cosign sign --yes --recursive "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.build.outputs.digest }}"
- name: Generate SBOM
run: |
trivy image --format cyclonedx --output sbom.json \
"${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.build.outputs.digest }}"
- name: Attest SBOM
run: |
cosign attest --yes --type cyclonedx --predicate sbom.json \
"${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.build.outputs.digest }}"
verify:
name: Verify Signature
needs: build-and-publish
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Install Cosign
uses: sigstore/cosign-installer@v4.1.0
- name: Verify signature
run: |
cosign verify "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}@${{ needs.build-and-publish.outputs.image_digest }}" \
--certificate-identity "https://github.com/${{ github.workflow_ref }}" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
publish-release:
name: Publish Release
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Publish Release
run: gh release edit "${{ github.ref_name }}" --draft=false
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}