Repository navigation
92 lines (81 loc) · 3.35 KB
/
Copy pathrelease.yaml
File metadata and controls
92 lines (81 loc) · 3.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
name: Publish release to Docker Hub
# Publishes the "major", "major.minor", and "major.minor.micro" tags. Replaces
# Docker Hub's Automated Builds, which retires on 2027-04-01:
# https://docs.docker.com/docker-hub/repos/manage/builds/migrate/
on:
push:
tags:
- "v*.*.*"
permissions:
contents: read
# Every release moves the "major" and "major.minor" tags, so two releases
# publishing at once could leave "9" pointing at the older of them.
concurrency:
group: dockerhub-release
cancel-in-progress: false
jobs:
check-version:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# test_image.py checks VERSION against CHANGELOG.md, but neither is checked
# against the tag being released.
- name: Check the Dockerfile version matches the tag
run: |
tag_version="${GITHUB_REF_NAME#v}"
dockerfile_version="$(
grep -m1 '^ENV VERSION=' Dockerfile \
| sed -E 's/^ENV VERSION=([0-9]+\.[0-9]+\.[0-9]+).*/\1/'
)"
if [ "${tag_version}" != "${dockerfile_version}" ]; then
echo "::error::Tag ${GITHUB_REF_NAME} is version ${tag_version}, but the Dockerfile sets VERSION=${dockerfile_version}. Bump VERSION, VERSION_MAJOR, VERSION_MINOR, and VERSION_MICRO in the Dockerfile before tagging a release."
exit 1
fi
echo "Dockerfile VERSION=${dockerfile_version} matches tag ${GITHUB_REF_NAME}."
publish:
needs: check-version
runs-on: ubuntu-latest
timeout-minutes: 60
environment: dockerhub-publish
permissions:
contents: read
id-token: write
steps:
- name: Check out the repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build and test the image
uses: ./.github/actions/build-test
# `latest=false` is required: the default would add a `latest` tag here and
# race latest.yaml, which owns `latest` on merges to master.
- name: Derive the Docker Hub tags
id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: civisanalytics/datascience-python
flavor: latest=false
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=semver,pattern={{major}}
# `password` is omitted deliberately: setting it switches the action out of
# OIDC mode and back to static credentials.
- name: Log in to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
env:
DOCKERHUB_OIDC_CONNECTIONID: ${{ vars.DOCKERHUB_OIDC_CONNECTIONID }}
with:
username: civisanalytics
# `provenance: false` keeps this a plain single-platform manifest. Buildx
# otherwise attaches attestations as extra manifests inside an image index,
# which not every client that pulls this image can handle.
- name: Build and push
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
target: production
push: true
tags: ${{ steps.meta.outputs.tags }}
provenance: false
sbom: false