From 8e86d1b539f2b98241139a5be76ba1876d563db1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C4=81ris=20Pop=C4=93ns?= Date: Sun, 4 Oct 2026 19:37:36 +0300 Subject: [PATCH] ci: publish the image via the reusable docker-publish workflow --- .github/workflows/build.yml | 48 ++++++------------------------------- 1 file changed, 7 insertions(+), 41 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 153198a..e7e41a6 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -17,51 +17,17 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +permissions: + contents: read + jobs: - build: - runs-on: ubuntu-latest + # Multi-arch image to GHCR plus SLSA provenance. Verify with: + # gh attestation verify oci://ghcr.io/drumandbytes/github-actions-runner-exporter:latest --owner drumandbytes + publish: permissions: contents: read packages: write id-token: write # Sigstore OIDC for build provenance attestations: write # record the attestation on the repo artifact-metadata: write # storage record for the pushed image - - steps: - - uses: actions/checkout@v7.0.1 - with: - persist-credentials: false - - - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 - id: meta - with: - images: ghcr.io/drumandbytes/github-actions-runner-exporter - tags: | - type=raw,value=latest,enable={{is_default_branch}} - type=sha,format=long - type=semver,pattern={{version}} - type=semver,pattern={{major}}.{{minor}} - - - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 - id: build - with: - context: . - platforms: linux/amd64,linux/arm64 - push: true - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - - # SLSA provenance, stored next to the image in GHCR. Verify with: - # gh attestation verify oci://ghcr.io/drumandbytes/github-actions-runner-exporter:latest --owner drumandbytes - - uses: actions/attest-build-provenance@v4.2.2 - with: - subject-name: ghcr.io/drumandbytes/github-actions-runner-exporter - subject-digest: ${{ steps.build.outputs.digest }} - push-to-registry: true + uses: drumandbytes/reusable-actions/.github/workflows/docker-publish.yml@v1