Skip to content

Bump actions/dependency-review-action from 3.0.6 to 4.3.4 (#476) #27

Bump actions/dependency-review-action from 3.0.6 to 4.3.4 (#476)

Bump actions/dependency-review-action from 3.0.6 to 4.3.4 (#476) #27

Workflow file for this run

name: Release
on:
push:
branches:
- main
# Publish `v1.2.3` tags as releases.
tags:
- v*
permissions: read-all
env:
IMAGE_NAME: packagefeeds
jobs:
# Push image to GitHub Packages.
push:
name: Push
runs-on: ubuntu-latest
permissions:
packages: write
id-token: write
contents: read
steps:
- uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3
- name: Install Cosign
uses: sigstore/cosign-installer@e1523de7571e31dbe865fd2e80c5c7c23ae71eb4 # v3.4.0
with:
cosign-release: 'v2.2.2'
- name: Log into registry
uses: docker/login-action@0d4c9c5ea7693da7b068278f7b52bda2a190a446
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set container metadata
uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5
id: docker-metadata
with:
images: ghcr.io/${{ github.repository }}/${{ env.IMAGE_NAME }}
labels: |
org.opencontainers.image.source=${{ github.repositoryUrl }}
org.opencontainers.image.description="This is a container for the Package Feeds process"
org.opencontainers.image.title="Package Feeds"
org.opencontainers.image.vendor="OpenSSF"
org.opencontainers.image.version=${{ github.sha }}
flavor: |
latest=auto
# Using the {{version}} placeholder to automatically detect the version from the git tag
# without the prefix "v".
# We'll also generate tags for commit sha, main branch changes and semver tags.
tags: |
type=sha
type=ref,event=tag
type=ref,event=branch
type=semver,pattern={{version}}
type=raw,value=latest,enable={{is_default_branch}}
- name: Build image
id: image-build
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
file: ./Dockerfile
tags: ${{ steps.docker-metadata.outputs.tags }}
labels: ${{ steps.docker-metadata.outputs.labels }}
provenance: true
sbom: true
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Sign the image
run: |
cosign sign --yes ghcr.io/${{ github.repository }}/${{ env.IMAGE_NAME }}@${{ steps.image-build.outputs.digest }}