From a7a30fb28220c0565a777a40675934f25eabc62b Mon Sep 17 00:00:00 2001 From: DaanSelen <80752476+DaanSelen@users.noreply.github.com> Date: Tue, 3 Jun 2025 15:19:11 +0200 Subject: [PATCH 1/4] Separated tasks (again) and separate builds (#8) --- .github/workflows/docker-build.yml | 86 ++++++++++++++++++++++++++++++ .github/workflows/docker-scan.yml | 37 +++++++++++++ .github/workflows/docker.yaml | 56 ------------------- 3 files changed, 123 insertions(+), 56 deletions(-) create mode 100644 .github/workflows/docker-build.yml create mode 100644 .github/workflows/docker-scan.yml delete mode 100644 .github/workflows/docker.yaml diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml new file mode 100644 index 0000000..d5d8c73 --- /dev/null +++ b/.github/workflows/docker-build.yml @@ -0,0 +1,86 @@ +name: Docker Build and Push + +on: + push: + branches: [main] + workflow_dispatch: + inputs: + trigger-build: + description: 'Trigger a manual build and push' + required: true + default: 'true' + +env: + DOCKER_HUB_PREFIX: docker.io + GHCR_PREFIX: ghcr.io + DOCKER_IMAGE: donaldzou/wgdashboard + +jobs: + docker_build: + runs-on: ubuntu-latest + strategy: + fail-fast: false + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Log in to Docker Hub + uses: docker/login-action@v3 + with: + registry: ${{ env.DOCKER_HUB_PREFIX }} + username: ${{ secrets.DOCKER_HUB_USERNAME }} + password: ${{ secrets.DOCKER_HUB_PASSWORD }} + + - name: Log in to GitHub Container Registry + uses: docker/login-action@v3 + with: + registry: ${{ env.GHCR_PREFIX }} + username: ${{ github.actor }} + password: ${{ secrets.GHCR_TOKEN }} + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + with: + platforms: linux/amd64,linux/arm64,linux/arm/v7 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Extract metadata (tags, labels) + id: meta + uses: docker/metadata-action@v5 + with: + images: | + ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }} + ${{ env.GHCR_PREFIX }}/${{ env.DOCKER_IMAGE }} + + - name: Build and export (multi-arch) + uses: docker/build-push-action@v6 + with: + context: . + file: ./docker/Dockerfile + push: true + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + platforms: linux/amd64,linux/arm64,linux/arm/v7 + + - name: Docker Scout CVEs + uses: docker/scout-action@v1 + with: + command: cves + image: ${{ steps.meta.outputs.tags }} + only-severities: critical,high + only-fixed: true + write-comment: true + github-token: ${{ secrets.GITHUB_TOKEN }} + exit-code: true + + - name: Docker Scout Compare + uses: docker/scout-action@v1 + with: + command: compare + image: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly + to: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:latest + only-severities: critical,high + ignore-unchanged: true + github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/docker-scan.yml b/.github/workflows/docker-scan.yml new file mode 100644 index 0000000..33a5ae3 --- /dev/null +++ b/.github/workflows/docker-scan.yml @@ -0,0 +1,37 @@ +name: Docker Scan + +on: + workflow_dispatch: + inputs: + trigger-scan: + description: 'Trigger a manual scan' + required: true + default: 'true' + +env: + DOCKER_IMAGE: donaldzou/wgdashboard + +jobs: + docker_scan: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Log in to Docker Hub + uses: docker/login-action@v3 + with: + registry: docker.io + username: ${{ secrets.DOCKER_HUB_USERNAME }} + password: ${{ secrets.DOCKER_HUB_PASSWORD }} + + - name: Docker Scout CVEs + uses: docker/scout-action@v1 + with: + command: cves + image: ${{ env.DOCKER_IMAGE }}:nightly + only-severities: critical,high + only-fixed: true + write-comment: true + github-token: ${{ secrets.GITHUB_TOKEN }} + exit-code: true diff --git a/.github/workflows/docker.yaml b/.github/workflows/docker.yaml deleted file mode 100644 index 8f75b36..0000000 --- a/.github/workflows/docker.yaml +++ /dev/null @@ -1,56 +0,0 @@ -name: Docker Scan and Build - -on: - push: - branches: [ main ] - schedule: - - cron: "0 0 * * *" # Daily at midnight UTC - workflow_dispatch: - inputs: - trigger-build: - description: 'Trigger a manual build and push' - default: 'true' - -env: - DOCKER_IMAGE: donaldzou/wgdashboard - -jobs: - docker_build_analyze: - runs-on: ubuntu-latest - strategy: - fail-fast: false - steps: - - name: Checkout repository - uses: actions/checkout@v4 - - - name: Log in to Docker Hub - uses: docker/login-action@v3 - with: - username: ${{ secrets.DOCKER_HUB_USERNAME }} - password: ${{ secrets.DOCKER_HUB_PASSWORD }} - - - name: Set up QEMU - uses: docker/setup-qemu-action@v3 - with: - platforms: linux/amd64,linux/arm64,linux/arm/v6,linux/arm/v7 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Build and export (multi-arch) - uses: docker/build-push-action@v6 - with: - context: . - file: ./docker/Dockerfile - push: true - tags: ${{ env.DOCKER_IMAGE }}:latest - platforms: linux/amd64,linux/arm64,linux/arm/v7 #ARM v6 no longer support by go image. - - - name: Docker Scout - id: docker-scout - uses: docker/scout-action@v1 - with: - command: cves - image: ${{ env.DOCKER_IMAGE }}:latest - only-severities: critical,high,medium,low,unspecified - github-token: ${{ secrets.GITHUB_TOKEN }} From 630ce459cb3f3af36fc7ee8fdd10360c0078b6ae Mon Sep 17 00:00:00 2001 From: Donald Zou Date: Wed, 4 Jun 2025 15:55:22 +0800 Subject: [PATCH 2/4] Update docker-build.yml Updated `GHCR_TOKEN` to `GITHUB_TOKEN` --- .github/workflows/docker-build.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml index d5d8c73..c79e59a 100644 --- a/.github/workflows/docker-build.yml +++ b/.github/workflows/docker-build.yml @@ -36,7 +36,7 @@ jobs: with: registry: ${{ env.GHCR_PREFIX }} username: ${{ github.actor }} - password: ${{ secrets.GHCR_TOKEN }} + password: ${{ secrets.GITHUB_TOKEN }} - name: Set up QEMU uses: docker/setup-qemu-action@v3 From 15c12a81f1e1943f8f324486f553d7bc58686482 Mon Sep 17 00:00:00 2001 From: Daan Selen Date: Wed, 4 Jun 2025 10:12:18 +0200 Subject: [PATCH 3/4] Separate stages --- .github/workflows/docker-build.yml | 42 ++++++++++++++++-------------- .github/workflows/docker-scan.yml | 37 -------------------------- 2 files changed, 23 insertions(+), 56 deletions(-) delete mode 100644 .github/workflows/docker-scan.yml diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml index c79e59a..f550b09 100644 --- a/.github/workflows/docker-build.yml +++ b/.github/workflows/docker-build.yml @@ -64,23 +64,27 @@ jobs: labels: ${{ steps.meta.outputs.labels }} platforms: linux/amd64,linux/arm64,linux/arm/v7 - - name: Docker Scout CVEs - uses: docker/scout-action@v1 - with: - command: cves - image: ${{ steps.meta.outputs.tags }} - only-severities: critical,high - only-fixed: true - write-comment: true - github-token: ${{ secrets.GITHUB_TOKEN }} - exit-code: true + docker_scan: + runs-on: ubuntu-latest + needs: docker_build + steps: + - name: Docker Scout CVEs + uses: docker/scout-action@v1 + with: + command: cves + image: ${{ needs.docker_build.outputs.image-tags }} + only-severities: critical,high + only-fixed: true + write-comment: true + github-token: ${{ secrets.GITHUB_TOKEN }} + exit-code: true - - name: Docker Scout Compare - uses: docker/scout-action@v1 - with: - command: compare - image: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly - to: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:latest - only-severities: critical,high - ignore-unchanged: true - github-token: ${{ secrets.GITHUB_TOKEN }} + - name: Docker Scout Compare + uses: docker/scout-action@v1 + with: + command: compare + image: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly + to: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:latest + only-severities: critical,high + ignore-unchanged: true + github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/docker-scan.yml b/.github/workflows/docker-scan.yml deleted file mode 100644 index 33a5ae3..0000000 --- a/.github/workflows/docker-scan.yml +++ /dev/null @@ -1,37 +0,0 @@ -name: Docker Scan - -on: - workflow_dispatch: - inputs: - trigger-scan: - description: 'Trigger a manual scan' - required: true - default: 'true' - -env: - DOCKER_IMAGE: donaldzou/wgdashboard - -jobs: - docker_scan: - runs-on: ubuntu-latest - steps: - - name: Checkout repository - uses: actions/checkout@v4 - - - name: Log in to Docker Hub - uses: docker/login-action@v3 - with: - registry: docker.io - username: ${{ secrets.DOCKER_HUB_USERNAME }} - password: ${{ secrets.DOCKER_HUB_PASSWORD }} - - - name: Docker Scout CVEs - uses: docker/scout-action@v1 - with: - command: cves - image: ${{ env.DOCKER_IMAGE }}:nightly - only-severities: critical,high - only-fixed: true - write-comment: true - github-token: ${{ secrets.GITHUB_TOKEN }} - exit-code: true From 84167650b8fd78067709d21f33259a18286fc0a4 Mon Sep 17 00:00:00 2001 From: Daan Selen Date: Wed, 4 Jun 2025 10:27:11 +0200 Subject: [PATCH 4/4] hotfix --- .github/workflows/docker-build.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/docker-build.yml b/.github/workflows/docker-build.yml index f550b09..ee4ab97 100644 --- a/.github/workflows/docker-build.yml +++ b/.github/workflows/docker-build.yml @@ -53,6 +53,11 @@ jobs: images: | ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }} ${{ env.GHCR_PREFIX }}/${{ env.DOCKER_IMAGE }} + tags: | + type=semver,pattern={{version}} + type=semver,pattern=latest,enable={{is_tag}} + type=raw,value=nightly,enable={{is_default_branch}} + type=ref,pattern={{ref_name}},enable={{is_default_branch}} - name: Build and export (multi-arch) uses: docker/build-push-action@v6 @@ -72,7 +77,7 @@ jobs: uses: docker/scout-action@v1 with: command: cves - image: ${{ needs.docker_build.outputs.image-tags }} + image: ${{ env.GHCR_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly only-severities: critical,high only-fixed: true write-comment: true @@ -83,8 +88,8 @@ jobs: uses: docker/scout-action@v1 with: command: compare - image: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly - to: ${{ env.DOCKER_HUB_PREFIX }}/${{ env.DOCKER_IMAGE }}:latest + image: ${{ env.GHCR_PREFIX }}/${{ env.DOCKER_IMAGE }}:nightly + to: ${{ env.GHCR_PREFIX }}/${{ env.DOCKER_IMAGE }}:latest only-severities: critical,high ignore-unchanged: true github-token: ${{ secrets.GITHUB_TOKEN }}