2020-08-09 21:13:25 +02:00
|
|
|
name: Docker builds
|
2020-08-09 20:32:02 +02:00
|
|
|
|
|
|
|
on:
|
|
|
|
pull_request:
|
2023-07-10 22:49:01 +02:00
|
|
|
branches: [master]
|
2020-08-09 20:32:02 +02:00
|
|
|
push:
|
2023-07-10 22:49:01 +02:00
|
|
|
branches: [master]
|
2020-08-09 20:32:02 +02:00
|
|
|
tags:
|
|
|
|
- v*
|
2024-08-29 15:25:25 +02:00
|
|
|
schedule:
|
|
|
|
- cron: '18 1 * * 4'
|
2021-03-29 12:36:14 +02:00
|
|
|
|
2021-03-28 23:03:42 +02:00
|
|
|
env:
|
|
|
|
DOCKER_USERNAME: viktorstrate
|
|
|
|
DOCKER_IMAGE: viktorstrate/photoview
|
|
|
|
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
2024-08-29 10:30:06 +02:00
|
|
|
PLATFORMS: linux/amd64,linux/arm64,linux/arm/v7,linux/arm/v6
|
2020-08-09 20:32:02 +02:00
|
|
|
|
|
|
|
jobs:
|
2024-08-29 15:25:25 +02:00
|
|
|
prepare:
|
|
|
|
name: Prepare the Matrix
|
|
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
|
|
- name: Checkout
|
|
|
|
uses: actions/checkout@v4
|
|
|
|
|
|
|
|
- name: Prepare the Matrix
|
|
|
|
id: prepare_matrix
|
|
|
|
shell: bash
|
|
|
|
run: |
|
|
|
|
case ${{ github.event_name }} in
|
|
|
|
pull_request)
|
|
|
|
echo 'tags=[{"tag": "", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
|
|
|
|
;;
|
|
|
|
push)
|
|
|
|
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
|
|
|
|
;;
|
|
|
|
schedule)
|
|
|
|
git fetch --all
|
|
|
|
TAG=$(git describe --tags --abbrev=0 || exit 0)
|
|
|
|
if [ -z "$TAG" ]; then
|
|
|
|
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
|
|
|
|
else
|
|
|
|
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}, {"tag": "$TAG", "ref": "$(git show-ref --tags -d | grep "/$TAG$" | cut -d ' ' -f 2)"}]' >> $GITHUB_OUTPUT
|
|
|
|
fi
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
echo "Run for '${{ github.event_name }}' is not expected"
|
|
|
|
echo 'tags=[{"tag": "", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
outputs:
|
|
|
|
tags: ${{ steps.prepare_matrix.outputs.tags }}
|
|
|
|
|
2020-08-09 21:13:25 +02:00
|
|
|
build:
|
2021-03-28 21:24:32 +02:00
|
|
|
name: Build Docker Image
|
2024-08-29 10:30:06 +02:00
|
|
|
runs-on: ubuntu-latest
|
2024-08-29 15:25:25 +02:00
|
|
|
needs: prepare
|
|
|
|
strategy:
|
|
|
|
fail-fast: false
|
|
|
|
matrix:
|
|
|
|
tags: ${{ fromJson(needs.prepare.outputs.tags) }}
|
2020-08-09 20:32:02 +02:00
|
|
|
steps:
|
2024-08-29 10:30:06 +02:00
|
|
|
- name: Delete huge unnecessary tools folder
|
|
|
|
run: rm -rf /opt/hostedtoolcache
|
2020-08-09 21:13:25 +02:00
|
|
|
|
2024-08-29 15:25:25 +02:00
|
|
|
- name: Checkout ${{ matrix.tags.ref }}
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: actions/checkout@v4
|
2024-08-29 15:25:25 +02:00
|
|
|
with:
|
|
|
|
ref: ${{ matrix.tags.ref }}
|
|
|
|
|
|
|
|
- name: Fetch branches
|
|
|
|
run: git fetch --all
|
2020-08-09 21:13:25 +02:00
|
|
|
|
2020-12-09 19:24:39 +01:00
|
|
|
- name: Set up QEMU
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: docker/setup-qemu-action@v3
|
2020-12-09 19:24:39 +01:00
|
|
|
with:
|
2024-08-29 10:30:06 +02:00
|
|
|
platforms: ${{ env.PLATFORMS }}
|
|
|
|
|
2020-12-09 19:24:39 +01:00
|
|
|
|
|
|
|
- name: Set up Docker Buildx
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: docker/setup-buildx-action@v3
|
2020-12-09 19:24:39 +01:00
|
|
|
|
2021-03-28 23:03:42 +02:00
|
|
|
- name: Docker Login
|
2024-08-29 15:25:25 +02:00
|
|
|
if: github.event_name != 'pull_request' && github.repository == 'photoview/photoview'
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: docker/login-action@v3
|
2023-07-10 18:37:18 +02:00
|
|
|
with:
|
|
|
|
username: ${{ env.DOCKER_USERNAME }}
|
|
|
|
password: ${{ env.DOCKER_PASSWORD }}
|
|
|
|
|
|
|
|
- name: Docker meta
|
|
|
|
id: docker_meta
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: docker/metadata-action@v5
|
2023-07-10 18:37:18 +02:00
|
|
|
with:
|
|
|
|
# list of Docker images to use as base name for tags
|
|
|
|
images: ${{ env.DOCKER_IMAGE }}
|
|
|
|
# Docker tags based on the following events/attributes
|
|
|
|
tags: |
|
|
|
|
type=schedule
|
|
|
|
type=ref,event=branch
|
|
|
|
type=ref,event=pr
|
|
|
|
type=semver,pattern={{version}}
|
|
|
|
type=semver,pattern={{major}}.{{minor}}
|
|
|
|
type=semver,pattern={{major}}
|
|
|
|
type=sha
|
|
|
|
|
|
|
|
- name: Build and push
|
2024-08-29 10:30:06 +02:00
|
|
|
uses: docker/build-push-action@v6
|
2023-07-10 18:37:18 +02:00
|
|
|
with:
|
|
|
|
context: .
|
2024-08-29 15:25:25 +02:00
|
|
|
sbom: true
|
|
|
|
provenance: mode=max
|
2024-08-29 10:30:06 +02:00
|
|
|
platforms: ${{ env.PLATFORMS }}
|
|
|
|
pull: true
|
2023-07-10 18:37:18 +02:00
|
|
|
push: ${{ github.event_name != 'pull_request' && github.repository == 'photoview/photoview' }}
|
|
|
|
tags: ${{ steps.docker_meta.outputs.tags }}
|
|
|
|
labels: ${{ steps.docker_meta.outputs.labels }}
|
2024-08-29 15:25:25 +02:00
|
|
|
annotations: ${{ steps.docker_meta.outputs.annotations }}
|
2024-08-29 10:30:06 +02:00
|
|
|
cache-from: type=gha
|
|
|
|
cache-to: type=gha,mode=max
|
2024-08-27 21:46:29 +02:00
|
|
|
build-args: |
|
|
|
|
VERSION=${{ github.ref_name }}
|
|
|
|
COMMIT_SHA=${{ github.sha }}
|
2024-08-29 15:25:25 +02:00
|
|
|
|
|
|
|
dockle:
|
|
|
|
name: Dockle Container Analysis
|
|
|
|
runs-on: ubuntu-latest
|
|
|
|
needs:
|
|
|
|
- prepare
|
|
|
|
- build
|
|
|
|
strategy:
|
|
|
|
fail-fast: false
|
|
|
|
matrix:
|
|
|
|
tags: ${{ fromJson(needs.prepare.outputs.tags) }}
|
|
|
|
if: ${{ github.event_name != 'pull_request' && github.repository == 'photoview/photoview' }}
|
|
|
|
steps:
|
|
|
|
# Makes sure your .dockleignore file is available to the next step
|
|
|
|
- name: Checkout ${{ matrix.tags.ref }}
|
|
|
|
uses: actions/checkout@v4
|
|
|
|
with:
|
|
|
|
ref: ${{ matrix.tags.ref }}
|
|
|
|
|
|
|
|
- name: Docker Login
|
|
|
|
uses: docker/login-action@v3
|
|
|
|
with:
|
|
|
|
username: ${{ env.DOCKER_USERNAME }}
|
|
|
|
password: ${{ env.DOCKER_PASSWORD }}
|
|
|
|
|
|
|
|
- name: Run Dockle for '${{ env.DOCKER_IMAGE }}:${{ matrix.tags.tag }}'
|
|
|
|
id: dockle
|
|
|
|
if: ${{ matrix.tags.tag != '' }}
|
|
|
|
uses: erzz/dockle-action@v1
|
|
|
|
with:
|
|
|
|
image: '${{ env.DOCKER_IMAGE }}:${{ matrix.tags.tag }}'
|
|
|
|
report-name: dockle-results-${{ matrix.tags.tag }}
|
|
|
|
report-format: sarif
|
|
|
|
failure-threshold: fatal
|
|
|
|
exit-code: 1
|
|
|
|
timeout: 5m
|
|
|
|
|
|
|
|
- name: Upload SARIF file
|
|
|
|
if: ${{ steps.dockle.conclusion == 'success' || steps.dockle.conclusion == 'failure' }}
|
|
|
|
uses: github/codeql-action/upload-sarif@v3
|
|
|
|
with:
|
|
|
|
sarif_file: dockle-results-${{ matrix.tags.tag }}.sarif
|