Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/docker-run/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ inputs:
required: true
image:
description: "The image to use"
default: "ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08"
default: "ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425"
required: false
workdir:
description: "The images working directory"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-beta.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@ jobs:

container:
# NOTE: This step only signs and uploads, so it doesn't need any privileges
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- name: Harden Runner
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/build-old.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
contents: read

container:
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425
# TODO: Deprivilege
options: |
--cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined
Expand Down Expand Up @@ -139,7 +139,7 @@ jobs:

container:
# NOTE: This step only signs and uploads, so it doesn't need any privileges
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- name: Harden Runner
Expand Down Expand Up @@ -262,7 +262,7 @@ jobs:

container:
# NOTE: This step only signs and uploads, so it doesn't need any privileges
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- name: Harden Runner
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-world.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
# permissions:

container:
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425
# TODO: Deprivilege
options: |
--cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
contents: read

container:
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425
# TODO: Deprivilege
options: |
--cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined
Expand Down Expand Up @@ -170,7 +170,7 @@ jobs:

container:
# NOTE: This step only signs and uploads, so it doesn't need any privileges
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- name: Harden Runner
Expand Down Expand Up @@ -293,7 +293,7 @@ jobs:

container:
# NOTE: This step only signs and uploads, so it doesn't need any privileges
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- name: Harden Runner
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/lint-world.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
group: wolfi-os-builder-${{ matrix.arch }}

container:
image: ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
image: ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
Expand Down
4 changes: 2 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -188,7 +188,7 @@ dev-container:
-v "${PWD}:${PWD}" \
-w "${PWD}" \
-e SOURCE_DATE_EPOCH=0 \
ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425

PACKAGES_CONTAINER_FOLDER ?= /work/packages
TMP_REPOSITORIES_DIR := $(shell mktemp -d)
Expand Down Expand Up @@ -253,6 +253,6 @@ dev-container-wolfi:
--mount type=bind,source="${PWD}/local-melange.rsa.pub",destination="/etc/apk/keys/local-melange.rsa.pub",readonly \
--mount type=bind,source="$(TMP_REPOSITORIES_FILE)",destination="/etc/apk/repositories",readonly \
-w "$(PACKAGES_CONTAINER_FOLDER)" \
ghcr.io/wolfi-dev/sdk:latest@sha256:defd6868c1ec7df43bff7a1e8856b5b7d79804603c1651262ea91741dd10bc08
ghcr.io/wolfi-dev/sdk:latest@sha256:7acd15c1b765550faec477069a7d0c8a1de329f220f8d7d1786ecbf3172e9425
@rm "$(TMP_REPOSITORIES_FILE)"
@rmdir "$(TMP_REPOSITORIES_DIR)"