mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* feat: Add separate package manager and resolver * fix: Npm dependency resolver * feat: Add analyzer for malysis query * feat: Add package manager guard as the orchestrator * feat: Add PMG to orchestrate installation * Add concurrent scan execution * Introduce package manager interaction abstraction * feat: Add UI port for guard * Remove refactored source files * Update README * fix: CI script for multi-arch build * ci: goreleaser CI fix * fix: npm command parser to extract package names * feat: Introduce global config primitive * fix: Close results channel for clean goroutine exit * ci: Add container image releaser * test: Improve test for npm resolver * refactor: Analyzer to generalise * Improve UI with additional info * fix: Goreleaser config * fix: npm resolver bug * fix: Fail when command exec workflow fails * fix: Bug with transitive dependency resolution * fix: Synchronize common data update in dependency resolver * chore: Improve log handling * docs: Update README * fix: UI text wrapping * fix: UI handling bugs * feat: Use concurrent dependency resolver
71 lines
1.9 KiB
YAML
71 lines
1.9 KiB
YAML
name: Container Image Releaser
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v[0-9]+.[0-9]+.[0-9]+"
|
|
branches:
|
|
- "main"
|
|
|
|
concurrency: ci-container-release
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
env:
|
|
REGISTRY: ghcr.io
|
|
IMAGE_NAME: ${{ github.repository }}
|
|
|
|
jobs:
|
|
build:
|
|
timeout-minutes: 30
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
id-token: write
|
|
|
|
steps:
|
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
|
|
with:
|
|
submodules: true
|
|
fetch-depth: 0
|
|
|
|
- name: Registry Login
|
|
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3
|
|
with:
|
|
registry: ${{ env.REGISTRY }}
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Setup QEMU
|
|
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3
|
|
|
|
- name: Setup Docker Buildx
|
|
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3
|
|
|
|
- name: Build and Push Container Image
|
|
run: |
|
|
# Get the tag if this was a tag push event
|
|
if [[ "${{ github.ref_type }}" == "tag" ]]; then
|
|
TAG=${{ github.ref_name }}
|
|
# Validate tag format (must be vX.Y.Z)
|
|
if [[ $TAG =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
|
# Build and push with both version tag and latest
|
|
docker buildx build --push --platform linux/amd64,linux/arm64 \
|
|
-t $REGISTRY/$IMAGE_NAME:$TAG \
|
|
-t $REGISTRY/$IMAGE_NAME:latest \
|
|
.
|
|
else
|
|
echo "Invalid tag format. Must be in format vX.Y.Z (e.g. v1.2.3)"
|
|
exit 1
|
|
fi
|
|
else
|
|
# For non-tag pushes, just use latest tag
|
|
docker buildx build --push --platform linux/amd64,linux/arm64 \
|
|
-t $REGISTRY/$IMAGE_NAME:latest \
|
|
.
|
|
fi
|
|
|
|
|