From e017fa3b49b50476d64cd1e57298c61761d04f26 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Tue, 7 Oct 2025 20:30:22 +0700 Subject: [PATCH] feat: update actions base on template --- .github/workflows/publish-couchbase-2.5.yml | 49 ++++++++++++------- .github/workflows/publish-gradle-8.yml | 52 ++++++++++++++------- .github/workflows/publish-oraclejdk-8.yml | 52 ++++++++++++++------- 3 files changed, 101 insertions(+), 52 deletions(-) diff --git a/.github/workflows/publish-couchbase-2.5.yml b/.github/workflows/publish-couchbase-2.5.yml index 0494ff6..3e27a2a 100644 --- a/.github/workflows/publish-couchbase-2.5.yml +++ b/.github/workflows/publish-couchbase-2.5.yml @@ -1,42 +1,59 @@ -name: Publish Couchbase 2.5 Docker Image +name: Publish Docker image on: push: - branches: [main] + branches: + - 'main' paths: - 'couchbase-2.5/**' workflow_dispatch: jobs: - build-and-push: + push_to_registries: + name: Push Docker image to multiple registries runs-on: ubuntu-latest permissions: - contents: read packages: write - + contents: read + attestations: write + id-token: write steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Check out the repo + uses: actions/checkout@v5 - - name: Log in to GitHub Container Registry - uses: docker/login-action@v2 + - name: Log in to Docker Hub + uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Log in to the Container registry + uses: docker/login-action@65b78e6e13532edd9afa3aa52ac7964289d1a9c1 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Extract metadata + - name: Extract metadata (tags, labels) for Docker id: meta - uses: docker/metadata-action@v4 + uses: docker/metadata-action@9ec57ed1fcdbf14dcef7dfbe97b2010124a938b7 with: - images: ghcr.io/${{ github.repository }}/couchbase-2.5 - tags: | - type=raw,value=latest + images: | + ${{ secrets.DOCKER_USERNAME }}/couchbase-2.5 + ghcr.io/${{ github.actor }}/couchbase-2.5 - - name: Build and push Docker image - uses: docker/build-push-action@v4 + - name: Build and push Docker images + id: push + uses: docker/build-push-action@3b5e8027fcad23fda98b2e3ac259d8d67585f671 with: context: couchbase-2.5 push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ghcr.io/${{ github.actor }}/couchbase-2.5 + subject-digest: ${{ steps.push.outputs.digest }} + push-to-registry: true diff --git a/.github/workflows/publish-gradle-8.yml b/.github/workflows/publish-gradle-8.yml index 792a2cd..c15919c 100644 --- a/.github/workflows/publish-gradle-8.yml +++ b/.github/workflows/publish-gradle-8.yml @@ -1,43 +1,59 @@ -name: Publish Gradle 8 Docker Image +name: Publish Docker image on: push: - branches: [main] + branches: + - 'main' paths: - 'gradle-8/**' workflow_dispatch: jobs: - build-and-push: + push_to_registries: + name: Push Docker image to multiple registries runs-on: ubuntu-latest permissions: - contents: read packages: write - + contents: read + attestations: write + id-token: write steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Check out the repo + uses: actions/checkout@v5 - - name: Log in to GitHub Container Registry - uses: docker/login-action@v2 + - name: Log in to Docker Hub + uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Log in to the Container registry + uses: docker/login-action@65b78e6e13532edd9afa3aa52ac7964289d1a9c1 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Extract metadata + - name: Extract metadata (tags, labels) for Docker id: meta - uses: docker/metadata-action@v4 + uses: docker/metadata-action@9ec57ed1fcdbf14dcef7dfbe97b2010124a938b7 with: - images: ghcr.io/${{ github.repository }}/gradle-8 - tags: | - type=raw,value=latest - type=raw,value=8.14.3 + images: | + ${{ secrets.DOCKER_USERNAME }}/gradle-8 + ghcr.io/${{ github.actor }}/gradle-8 - - name: Build and push Docker image - uses: docker/build-push-action@v4 + - name: Build and push Docker images + id: push + uses: docker/build-push-action@3b5e8027fcad23fda98b2e3ac259d8d67585f671 with: context: gradle-8 push: true tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} \ No newline at end of file + labels: ${{ steps.meta.outputs.labels }} + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ghcr.io/${{ github.actor }}/gradle-8 + subject-digest: ${{ steps.push.outputs.digest }} + push-to-registry: true diff --git a/.github/workflows/publish-oraclejdk-8.yml b/.github/workflows/publish-oraclejdk-8.yml index 8b1d3dc..0825171 100644 --- a/.github/workflows/publish-oraclejdk-8.yml +++ b/.github/workflows/publish-oraclejdk-8.yml @@ -1,43 +1,59 @@ -name: Publish Oracle JDK 8 Docker Image +name: Publish Docker image on: push: - branches: [main] + branches: + - 'main' paths: - 'oraclejdk-8/**' workflow_dispatch: jobs: - build-and-push: + push_to_registries: + name: Push Docker image to multiple registries runs-on: ubuntu-latest permissions: - contents: read packages: write - + contents: read + attestations: write + id-token: write steps: - - name: Checkout - uses: actions/checkout@v3 + - name: Check out the repo + uses: actions/checkout@v5 - - name: Log in to GitHub Container Registry - uses: docker/login-action@v2 + - name: Log in to Docker Hub + uses: docker/login-action@f4ef78c080cd8ba55a85445d5b36e214a81df20a + with: + username: ${{ secrets.DOCKER_USERNAME }} + password: ${{ secrets.DOCKER_PASSWORD }} + + - name: Log in to the Container registry + uses: docker/login-action@65b78e6e13532edd9afa3aa52ac7964289d1a9c1 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - name: Extract metadata + - name: Extract metadata (tags, labels) for Docker id: meta - uses: docker/metadata-action@v4 + uses: docker/metadata-action@9ec57ed1fcdbf14dcef7dfbe97b2010124a938b7 with: - images: ghcr.io/${{ github.repository }}/oraclejdk-8 - tags: | - type=raw,value=latest - type=raw,value=8u201 + images: + ${{ secrets.DOCKER_USERNAME }}/oraclejdk-8 + ghcr.io/${{ github.actor }}/oraclejdk-8 - - name: Build and push Docker image - uses: docker/build-push-action@v4 + - name: Build and push Docker images + id: push + uses: docker/build-push-action@3b5e8027fcad23fda98b2e3ac259d8d67585f671 with: context: oraclejdk-8 push: true tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} \ No newline at end of file + labels: ${{ steps.meta.outputs.labels }} + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v3 + with: + subject-name: ghcr.io/${{ github.actor }}/oraclejdk-8 + subject-digest: ${{ steps.push.outputs.digest }} + push-to-registry: true