Commit Graph
6 Commits
Author SHA1 Message Date
xixu-me ffe6da53c2 Update Trivy scan to use tag instead of digest
Added debug output steps and changed the Trivy vulnerability scanner to reference the image by tag (${github.ref_name}) instead of digest. This helps with debugging and aligns the scan with the tagged image.
2025-08-19 21:21:45 +08:00
xixu-me 8c969b6bbf Update Docker workflow to use image digest for Trivy scan
Adds outputs for image tags and digest in the build-and-push job and updates the Trivy scanner to reference the image by digest instead of the latest tag. This ensures the vulnerability scan is performed on the exact built image.
2025-08-19 21:11:16 +08:00
xixu-me d9cabc4436 Add attestations permission to Docker workflow
Grants the 'attestations: write' permission in the GitHub Actions Docker workflow to enable writing attestations. This may be required for enhanced security or provenance features.
2025-08-19 21:04:37 +08:00
xixu-me d4a4f2f373 Fix Docker digest output reference in workflow
Updates the GitHub Actions workflow to use the correct step ID 'build-and-push' for the Docker image digest output, ensuring the provenance attestation references the correct value.
2025-08-19 21:00:48 +08:00
xixu-me f6d96c4e6c Add id-token write permission to Docker workflow
Grants the workflow 'id-token: write' permission, which may be required for certain authentication steps or integrations in the Docker build and publish process.
2025-08-19 20:55:47 +08:00
xixu-me 5281b33bcc Add Docker support and server entrypoint
Introduced Dockerfile, .dockerignore, and GitHub Actions workflow for building and publishing Docker images. Added server.js as the Express entrypoint for standalone deployment. Updated README with Docker, Docker Compose, and Kubernetes deployment instructions.
2025-08-19 20:37:29 +08:00