Files
xget/.github/workflows/image.yml
T
xixu-me 58a0835213 Ignore docs and config files in CI workflow triggers
Updated the GitHub Actions workflow to ignore changes in markdown files, documentation, test, scripts, and common config files when triggering on push and pull_request events. This reduces unnecessary workflow runs for non-code changes.
2025-08-19 21:44:49 +08:00

130 lines
3.5 KiB
YAML

name: Build and Push Image
on:
push:
branches:
- main
- develop
tags:
- 'v*'
paths-ignore:
- '**.md'
- 'docs/**'
- 'test/**'
- 'scripts/**'
- '.gitignore'
- '.editorconfig'
- 'LICENSE'
pull_request:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
- 'test/**'
- 'scripts/**'
- '.gitignore'
- '.editorconfig'
- 'LICENSE'
workflow_dispatch:
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
build-and-push:
runs-on: ubuntu-latest
outputs:
image-tags: ${{ steps.meta.outputs.tags }}
image-digest: ${{ steps.build-and-push.outputs.digest }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=semver,pattern={{major}}
type=sha,prefix={{branch}}-
type=raw,value=latest,enable={{is_default_branch}}
- name: Build and push image
id: build-and-push
uses: docker/build-push-action@v5
with:
context: .
file: ./Dockerfile
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
platforms: linux/amd64,linux/arm64
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Generate artifact attestation
uses: actions/attest-build-provenance@v1
with:
subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}}
subject-digest: ${{ steps.build-and-push.outputs.digest }}
push-to-registry: true
security-scan:
runs-on: ubuntu-latest
needs: build-and-push
if: github.event_name != 'pull_request'
permissions:
contents: read
packages: read
security-events: write
steps:
- name: Debug outputs
run: |
echo "Image tags: ${{ needs.build-and-push.outputs.image-tags }}"
echo "Image digest: ${{ needs.build-and-push.outputs.image-digest }}"
echo "Registry: ${{ env.REGISTRY }}"
echo "Image name: ${{ env.IMAGE_NAME }}"
- name: Set image for scanning
id: scan-image
run: |
FIRST_TAG=$(echo "${{ needs.build-and-push.outputs.image-tags }}" | head -n1)
echo "image-ref=${FIRST_TAG}" >> $GITHUB_OUTPUT
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ steps.scan-image.outputs.image-ref }}
format: 'sarif'
output: 'trivy-results.sarif'
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: 'trivy-results.sarif'