Skip to content

chore(deps): bump the actions group with 4 updates (#93) #6

chore(deps): bump the actions group with 4 updates (#93)

chore(deps): bump the actions group with 4 updates (#93) #6

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# Publish the checky-monkey FFI library image to GHCR so the
# ghcr.io/hyperpolymath/checky-monkey package links back to this repo via the
# org.opencontainers.image.source label injected by metadata-action.
name: Publish Image
on:
push:
branches: [main]
paths:
- 'ffi/zig/**'
- 'Containerfile'
- '.github/workflows/publish-image.yml'
workflow_dispatch: {}
permissions:
contents: read
jobs:
build-push:
name: Build and push image
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: read
packages: write
id-token: write
attestations: write
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Log in to GHCR
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: ghcr.io/hyperpolymath/checky-monkey
tags: |
type=raw,value=latest,enable={{is_default_branch}}
type=sha
- name: Build and push
id: push
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v6
with:
context: .
file: ./Containerfile
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Attest container provenance
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ghcr.io/hyperpolymath/checky-monkey
subject-digest: ${{ steps.push.outputs.digest }}
push-to-registry: true