-
Notifications
You must be signed in to change notification settings - Fork 19
Expand file tree
/
Copy pathdeploy-docker-image-release.yml
More file actions
102 lines (87 loc) 路 3.28 KB
/
Copy pathdeploy-docker-image-release.yml
File metadata and controls
102 lines (87 loc) 路 3.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
name: Deploy - Docker Image Release
on:
push:
tags:
- 'v*'
permissions:
contents: write
security-events: write
jobs:
buildandpush:
runs-on: ubuntu-latest
# Docs: https://docs.github.com/en/actions/deployment/about-deployments/deploying-with-github-actions
environment: dockerhub
steps:
- name: Check out the repo
uses: actions/checkout@v7
- name: Extract tag name
id: extract_tag
run: echo "TAG_NAME=${GITHUB_REF#refs/tags/v}" >> $GITHUB_ENV
- name: Login to Docker Hub
uses: docker/login-action@v4
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Build the Docker image
run: |
docker build . --file Dockerfile --tag "devops-toolkit-release:${{ env.TAG_NAME }}"
- name: Verify tool versions
run: |
cd scripts
chmod +x check_version_in_toolkit.sh
./check_version_in_toolkit.sh "devops-toolkit-release:${{ env.TAG_NAME }}" "../toolkit_info.json"
- name: Running Sample Tool Code
run: |
echo "Run sample tool code inside toolkit"
docker run --rm devops-toolkit-release:${{ env.TAG_NAME }} samples/run_sample.sh
- name: Scan image with Trivy (SARIF for Security tab)
uses: aquasecurity/trivy-action@v0.36.0
with:
image-ref: 'devops-toolkit-release:${{ env.TAG_NAME }}'
format: 'sarif'
output: 'trivy-results.sarif'
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
ignore-unfixed: true
- name: Upload Trivy results to the Security tab
uses: github/codeql-action/upload-sarif@v4.37.8
if: always()
with:
sarif_file: 'trivy-results.sarif'
- name: Block publish on fixable CRITICAL/HIGH vulnerabilities
uses: aquasecurity/trivy-action@v0.36.0
with:
image-ref: 'devops-toolkit-release:${{ env.TAG_NAME }}'
format: 'table'
exit-code: '1'
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
ignore-unfixed: true
- name: Generate SBOM
uses: anchore/sbom-action@v0
with:
image: 'devops-toolkit-release:${{ env.TAG_NAME }}'
format: 'cyclonedx-json'
output-file: 'sbom.cyclonedx.json'
- name: Upload SBOM artifact
uses: actions/upload-artifact@v7
with:
name: sbom-${{ env.TAG_NAME }}
path: sbom.cyclonedx.json
retention-days: 365
- name: Push Docker Image
run: |
docker tag "devops-toolkit-release:${{ env.TAG_NAME }}" "tungbq/devops-toolkit:${{ env.TAG_NAME }}"
docker tag "devops-toolkit-release:${{ env.TAG_NAME }}" "tungbq/devops-toolkit:latest"
docker images
echo "Push image with TAG_NAME"
docker push "tungbq/devops-toolkit:${{ env.TAG_NAME }}"
echo "Push latest image"
docker push "tungbq/devops-toolkit:latest"
- name: Docker Hub Description
uses: peter-evans/dockerhub-description@v5
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
repository: tungbq/devops-toolkit
enable-url-completion: true