Compare commits

...
86 Commits
Author SHA1 Message Date
Marcus Young 38eb73c946 [Automated 🤖 ] Bump to version 2.328.0 2025-08-13 11:50:10 -05:00
myoung34andGitHub 6f9d5e009f Merge pull request #478 from myoung34/renovate/actions-checkout-5.x
Update actions/checkout action to v5
2025-08-12 11:50:32 -05:00
myoung34andGitHub bb96d0442d Merge pull request #479 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.9
2025-08-12 07:59:46 -05:00
renovate[bot]andGitHub 4bcb02dcec Update github/codeql-action action to v3.29.9 2025-08-12 12:58:40 +00:00
renovate[bot]andGitHub 2cb239d5d3 Update actions/checkout action to v5 2025-08-11 13:40:28 +00:00
myoung34andGitHub 2d228ec756 Merge pull request #477 from myoung34/renovate/actions-checkout-4.x
Update actions/checkout action to v4.3.0
2025-08-11 08:40:06 -05:00
renovate[bot]andGitHub 01e2356778 Update actions/checkout action to v4.3.0 2025-08-11 13:22:41 +00:00
myoung34andGitHub 94dc8d1fc4 Merge pull request #476 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.8
2025-08-08 09:51:50 -05:00
renovate[bot]andGitHub eb4cdae200 Update github/codeql-action action to v3.29.8 2025-08-08 13:03:38 +00:00
myoung34andGitHub 5d7272cb81 Merge pull request #475 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.7
2025-08-07 16:22:34 -05:00
renovate[bot]andGitHub 807966fd8a Update github/codeql-action action to v3.29.7 2025-08-07 21:22:02 +00:00
myoung34andGitHub 35bcf6356f Merge pull request #474 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.6
2025-08-07 11:45:55 -05:00
renovate[bot]andGitHub 55792e9e0d Update github/codeql-action action to v3.29.6 2025-08-07 16:38:08 +00:00
myoung34andGitHub 39d1fb9176 Merge pull request #473 from myoung34/renovate/docker-login-action-3.x
Update docker/login-action action to v3.5.0
2025-08-04 10:38:10 -05:00
renovate[bot]andGitHub 64f5a4f958 Update docker/login-action action to v3.5.0 2025-08-04 14:58:28 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
ae3e836a6b Update dependency shellcheck to v0.11.0 (#472)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-08-04 06:07:00 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
cd0ae04c45 Update github/codeql-action action to v3.29.5 (#470)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-07-30 05:47:24 +00:00
Marcus Young 81e09ddc65 [Automated 🤖 ] Bump to version 2.327.1 2025-07-25 11:20:08 -05:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
fcb09013a4 Update github/codeql-action action to v3.29.4 (#468)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-07-23 21:14:56 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
b879b98f0d Update github/codeql-action action to v3.29.3 (#467)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-07-22 23:44:43 +00:00
Marcus Young e4df714376 [Automated 🤖 ] Bump to version 2.327.0 2025-07-22 13:50:50 -05:00
myoung34andGitHub 176b4f862d Merge pull request #465 from ElsevierAlex/allow-runner-name-without-prefix
Allow hostname without github-runner prefix to avoid 64-char limit
2025-07-14 08:01:53 -05:00
chorbea bf1835f3ee Defaulted RUNNER_NAME_PREFIX 2025-07-14 09:23:52 +01:00
Marcus Young 1113f5896b [Automated 🤖 ] Bump to version 2.326.0 2025-07-07 15:19:13 -05:00
chorbea a4c88c50ff allow hostname without github-runner prefix to avoid 64-char limit 2025-07-04 10:11:55 +01:00
myoung34andGitHub 6510abfa97 Merge pull request #464 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.2
2025-07-02 20:25:12 -04:00
renovate[bot]andGitHub 1e5aef7fd9 Update github/codeql-action action to v3.29.2 2025-06-30 16:25:17 +00:00
myoung34andGitHub 767b90dc11 Merge pull request #463 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.1
2025-06-27 06:55:11 -05:00
renovate[bot]andGitHub c4cde09fb4 Update github/codeql-action action to v3.29.1 2025-06-27 11:46:24 +00:00
myoung34andGitHub 93215e94d9 Merge pull request #461 from myoung34/renovate/docker-setup-buildx-action-3.x
Update docker/setup-buildx-action action to v3.11.1
2025-06-18 10:56:12 -05:00
renovate[bot]andGitHub cb4c4ac8ed Update docker/setup-buildx-action action to v3.11.1 2025-06-18 13:43:01 +00:00
myoung34andGitHub ba68ffeb81 Merge pull request #460 from myoung34/renovate/docker-setup-buildx-action-3.x
Update docker/setup-buildx-action action to v3.11.0
2025-06-16 14:12:03 -05:00
renovate[bot]andGitHub 6311c21d14 Update docker/setup-buildx-action action to v3.11.0 2025-06-16 19:07:01 +00:00
myoung34andGitHub b3c7474675 Merge pull request #458 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.29.0
2025-06-11 17:17:04 -05:00
renovate[bot]andGitHub b67116f6e4 Update github/codeql-action action to v3.29.0 2025-06-11 22:03:48 +00:00
myoung34andGitHub 1d9e8868ad Merge pull request #457 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.19
2025-06-03 10:20:18 -05:00
renovate[bot]andGitHub 2d4990e197 Update github/codeql-action action to v3.28.19 2025-06-03 15:10:37 +00:00
Marcus Young 7e5779b170 [Automated 🤖 ] Bump to version 2.325.0 2025-06-02 13:48:39 -05:00
myoung34andGitHub 56233b5a1c Merge pull request #455 from SaschaHenning/master
Fix RUNNER_WORKDIR not created if part of the folder structure is nonexisting
2025-05-22 09:54:58 -05:00
Sascha HenningandGitHub 2b0f61916a fix RUNNER_WORKDIR not created if parent folder does not exist 2025-05-20 15:01:32 +02:00
myoung34andGitHub d49ef96679 Merge pull request #454 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.18
2025-05-19 11:22:45 -05:00
renovate[bot]andGitHub f66226db9c Update github/codeql-action action to v3.28.18 2025-05-16 14:56:08 +00:00
Marcus Young de943e2e38 [Automated 🤖 ] Bump to version 2.324.0 2025-05-13 00:27:05 -05:00
myoung34andGitHub d9094bd6dd Merge pull request #448 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.17
2025-05-02 06:21:22 -04:00
renovate[bot]andGitHub 46bb16d631 Update github/codeql-action action to v3.28.17 2025-05-02 09:58:26 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
b304a0e3f1 Update actions/setup-python action to v5.6.0 (#447)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-04-24 14:31:26 +00:00
myoung34andGitHub 67197609ff Merge pull request #446 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.16
2025-04-23 08:07:01 -05:00
renovate[bot]andGitHub 4aa08f7b87 Update github/codeql-action action to v3.28.16 2025-04-23 12:48:24 +00:00
myoung34andGitHub c07669d21e Merge pull request #444 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.15
2025-04-07 20:42:58 -05:00
renovate[bot]andGitHub afe24fb382 Update github/codeql-action action to v3.28.15 2025-04-07 22:49:35 +00:00
myoung34andGitHub 4593a2c53b Merge pull request #443 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.14
2025-04-07 09:06:09 -05:00
renovate[bot]andGitHub febe59b6f2 Update github/codeql-action action to v3.28.14 2025-04-07 10:01:29 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
abf6f7ef87 Update actions/setup-python action to v5.5.0 (#441)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-03-25 10:46:47 +00:00
renovate[bot]GitHubrenovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
8969c0a49b Update github/codeql-action action to v3.28.13 (#439)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-03-24 22:14:27 +00:00
myoung34andGitHub ac1308d764 Merge pull request #438 from myoung34/renovate/github-codeql-action-3.x
Update github/codeql-action action to v3.28.12
2025-03-20 15:45:29 -05:00
renovate[bot]andGitHub c90771d489 Update github/codeql-action action to v3.28.12 2025-03-19 18:39:17 +00:00
Mark Young 5869f38e4b [Automated 🤖 ] Bump to version 2.323.0 2025-03-19 13:38:45 -05:00
Mark Young 9e608c3a82 Move final actions to SHA's 2025-03-17 11:11:33 -05:00
Mark Young b65e08bc91 Add codeql to flag unpinned actions refs 2025-03-17 09:15:06 -05:00
myoung34andGitHub 9270f9a7a7 Merge pull request #437 from myoung34/renovate/docker-setup-qemu-action-3.x
Update docker/setup-qemu-action action to v3.6.0
2025-03-17 08:56:15 -05:00
myoung34andGitHub 4e8ac02be6 Merge pull request #436 from myoung34/renovate/docker-setup-buildx-action-3.x
Update docker/setup-buildx-action action to v3.10.0
2025-03-17 08:56:08 -05:00
myoung34andGitHub 6c30d2e070 Merge pull request #435 from myoung34/renovate/docker-login-action-3.x
Update docker/login-action action to v3.4.0
2025-03-17 08:56:00 -05:00
renovate[bot]andGitHub 5aadc7f42b Update docker/setup-qemu-action action to v3.6.0 2025-03-17 13:55:49 +00:00
myoung34andGitHub 66eb4f5a2f Merge pull request #434 from myoung34/renovate/actions-stale-9.x
Update actions/stale action to v9.1.0
2025-03-17 08:55:47 -05:00
renovate[bot]andGitHub e42df8f308 Update docker/setup-buildx-action action to v3.10.0 2025-03-17 13:55:43 +00:00
myoung34andGitHub feedfa66f0 Merge pull request #433 from myoung34/renovate/actions-setup-python-5.x
Update actions/setup-python action to v5.4.0
2025-03-17 08:55:41 -05:00
renovate[bot]andGitHub 1f125c1391 Update docker/login-action action to v3.4.0 2025-03-17 13:55:38 +00:00
renovate[bot]andGitHub 9d6d26c2d4 Update actions/stale action to v9.1.0 2025-03-17 13:55:33 +00:00
renovate[bot]andGitHub 5cfbf3423a Update actions/setup-python action to v5.4.0 2025-03-17 13:55:30 +00:00
myoung34andGitHub ad78bd8fd8 Merge pull request #432 from myoung34/renovate/actions-create-release-1.x
Update actions/create-release action to v1.1.4
2025-03-17 08:55:25 -05:00
myoung34andGitHub 90fdc6b19c Merge pull request #431 from myoung34/renovate/actions-checkout-4.x
Update actions/checkout action to v4.2.2
2025-03-17 08:55:13 -05:00
myoung34andGitHub 8a526ec997 Merge pull request #430 from myoung34/renovate/nick-fields-retry-3.x
Update nick-fields/retry action to v3.0.2
2025-03-17 08:55:03 -05:00
renovate[bot]andGitHub 9c9369a0e3 Update actions/create-release action to v1.1.4 2025-03-17 13:53:52 +00:00
renovate[bot]andGitHub a79e0182bf Update actions/checkout action to v4.2.2 2025-03-17 13:53:49 +00:00
renovate[bot]andGitHub 2b58586d88 Update nick-fields/retry action to v3.0.2 2025-03-17 13:53:45 +00:00
myoung34andGitHub c1292d5720 Merge pull request #429 from myoung34/renovate/pin-dependencies
Pin dependencies
2025-03-17 08:53:12 -05:00
renovate[bot]andGitHub e8e9da59f0 Pin dependencies 2025-03-17 13:27:33 +00:00
Mark Young d8df91da6d Set renovate to prefer github actions sha's 2025-03-17 08:26:55 -05:00
myoung34andGitHub 651dbe1fdf Merge pull request #427 from myoung34/fix_deregistration_on_reusable
Force DISABLE_AUTOMATIC_DEREGISTRATION to be true on reusable runners, add tests
2025-02-24 11:56:18 -06:00
Mark Young 9ed37bca4c Force DISABLE_AUTOMATIC_DEREGISTRATION to be true on reusable runners, add tests 2025-02-24 11:19:25 -06:00
Mark Young b9c038dfd3 Fix remaining qemu libc-bin runs 2025-02-19 17:30:16 -06:00
myoung34andGitHub 38e96633b7 Merge pull request #425 from myoung34/libc-bin_segfault
Attempt to fix GHA segfault
2025-02-19 17:03:43 -06:00
Mark Young fb13e93b86 Fix GHA segfault on ubuntu-jammy for libc-bin
* backtrack binfmt to v7 via https://github.com/tonistiigi/binfmt/issues/240
2025-02-19 09:50:25 -06:00
Marcus Young c3436f8af3 [Automated 🤖 ] Bump to version 2.322.0 2025-01-24 09:00:57 -06:00
myoung34andGitHub 1a5ad74d28 Merge pull request #417 from myoung34/fix_debian_sid
Fix debian sid
2024-12-11 16:44:11 -05:00
Mark Young 50340d28c3 Fix debian sid 2024-12-11 15:59:31 -05:00
16 changed files with 279 additions and 107 deletions
+3
View File
@@ -0,0 +1,3 @@
query-filters:
- include:
id: actions/unpinned-tag
+43 -27
View File
@@ -21,13 +21,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile.base Dockerfile.base.ubuntu-${{ matrix.release }}; sed -i.bak 's/FROM.*/FROM ubuntu:${{ matrix.release }}/' Dockerfile.base.ubuntu-${{ matrix.release }}
- name: Install Goss and dgoss
@@ -41,12 +43,12 @@ jobs:
id: testvars
run: echo "GH_RUNNER_IMAGE=ubuntu-${{ matrix.release }}-${{ env.GIT_SHA }}-${{ matrix.platform }}" >> $GITHUB_ENV
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and load
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -61,7 +63,7 @@ jobs:
--cache-to type=gha,mode=max \
.
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -70,6 +72,9 @@ jobs:
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
debian_base_tests:
runs-on: ubuntu-latest
@@ -80,13 +85,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile.base Dockerfile.base.debian-${{ matrix.release }}; sed -i.bak 's/FROM.*/FROM debian:${{ matrix.release }}/' Dockerfile.base.debian-${{ matrix.release }}
- name: Install Goss and dgoss
@@ -100,12 +107,12 @@ jobs:
id: testvars
run: echo "GH_RUNNER_IMAGE=debian-${{ matrix.release }}-${{ env.GIT_SHA }}-${{ matrix.platform }}" >> $GITHUB_ENV
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -120,7 +127,7 @@ jobs:
--cache-to type=gha,mode=max \
.
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -129,6 +136,9 @@ jobs:
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
ubuntu_base_latest_deploy:
@@ -136,20 +146,22 @@ jobs:
needs: ubuntu_base_tests
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -172,22 +184,24 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile.base Dockerfile.base.ubuntu-${{ matrix.release }}; sed -i.bak 's/FROM.*/FROM ubuntu:${{ matrix.release }}/' Dockerfile.base.ubuntu-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -210,22 +224,24 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile.base Dockerfile.base.debian-${{ matrix.release }}; sed -i.bak 's/FROM.*/FROM debian:${{ matrix.release }}/' Dockerfile.base.debian-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
+30
View File
@@ -0,0 +1,30 @@
name: CodeQL Security Analysis
on:
push:
branches: [master]
jobs:
analyze:
name: Analyze GitHub Actions YAML
runs-on: ubuntu-latest
permissions:
security-events: write
actions: read
contents: read
steps:
- name: Checkout repository
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Initialize CodeQL
uses: github/codeql-action/init@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9
with:
languages: "actions"
queries: security-extended
config-file: .github/codeql/codeql-config.yml
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9
with:
category: "/language:actions"
+79 -30
View File
@@ -24,13 +24,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.ubuntu-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:ubuntu-${{ matrix.release }}/" Dockerfile.ubuntu-${{ matrix.release }}
- name: Install Goss and dgoss
@@ -44,12 +46,12 @@ jobs:
id: testvars
run: echo "GH_RUNNER_IMAGE=ubuntu-${{ matrix.release }}-${{ env.GIT_SHA }}-${{ matrix.platform }}" >> $GITHUB_ENV
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and load
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -65,7 +67,7 @@ jobs:
.
# Tests will run against the final `${GH_RUNNER_IMAGE}` laid on top of `base-${GH_RUNNER_IMAGE}`
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -73,10 +75,31 @@ jobs:
echo "os: ubuntu" >goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
# test the edge case from deregistration on reusable runners
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_reusage_fail.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
-e ACCESS_TOKEN=notreal \
-e LABELS=linux,x64 \
-e REPO_URL=https://github.com/octokode/test1 \
-e RUNNER_NAME=sustainjane-runner-1 \
-e RUNNER_SCOPE=repo \
-e RUNNER_WORKDIR=/tmp/runner/work \
-e DISABLE_AUTOMATIC_DEREGISTRATION=false \
-e CONFIGURED_ACTIONS_RUNNER_FILES_DIR=/runner/data \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the base
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the final image but with all defaults
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_full_defaults.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the final image but with non-default values
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_full.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
@@ -100,6 +123,9 @@ jobs:
-e EPHEMERAL=true \
-e DISABLE_AUTO_UPDATE=true \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
debian_tests:
runs-on: ubuntu-latest
@@ -110,13 +136,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.debian-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:debian-${{ matrix.release }}/" Dockerfile.debian-${{ matrix.release }}
- name: Install Goss and dgoss
@@ -130,12 +158,12 @@ jobs:
id: testvars
run: echo "GH_RUNNER_IMAGE=debian-${{ matrix.release }}-${{ env.GIT_SHA }}-${{ matrix.platform }}" >> $GITHUB_ENV
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Retry build and load
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -151,7 +179,7 @@ jobs:
.
# Tests will run against the final `${GH_RUNNER_IMAGE}` laid on top of `base-${GH_RUNNER_IMAGE}`
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -159,6 +187,21 @@ jobs:
echo "os: debian" >goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
# test the edge case from deregistration on reusable runners
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_reusage_fail.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
-e ACCESS_TOKEN=notreal \
-e LABELS=linux,x64 \
-e REPO_URL=https://github.com/octokode/test1 \
-e RUNNER_NAME=sustainjane-runner-1 \
-e RUNNER_SCOPE=repo \
-e RUNNER_WORKDIR=/tmp/runner/work \
-e DISABLE_AUTOMATIC_DEREGISTRATION=false \
-e CONFIGURED_ACTIONS_RUNNER_FILES_DIR=/runner/data \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the base
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
# test the final image but with all defaults
@@ -192,28 +235,30 @@ jobs:
needs: ubuntu_tests
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Update Dockerfile FROM org
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -238,28 +283,30 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.ubuntu-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:ubuntu-${{ matrix.release }}/" Dockerfile.ubuntu-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -284,28 +331,30 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.debian-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:debian-${{ matrix.release }}/" Dockerfile.debian-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
+26 -20
View File
@@ -14,10 +14,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Create Release
id: create_release
uses: actions/create-release@v1
uses: actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1.1.4
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
@@ -31,30 +31,32 @@ jobs:
needs: create-release
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: get version
run: echo 'TAG='${GITHUB_REF#refs/tags/} >> $GITHUB_ENV
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Update Dockerfile FROM org
run: sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:latest/" Dockerfile
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -79,30 +81,32 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: get version
run: echo 'TAG='${GITHUB_REF#refs/tags/} >> $GITHUB_ENV
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.ubuntu-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:ubuntu-${{ matrix.release }}/" Dockerfile.ubuntu-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -126,30 +130,32 @@ jobs:
needs: create-release
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: get version
run: echo 'TAG='${GITHUB_REF#refs/tags/} >> $GITHUB_ENV
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Copy Dockerfile
run: cp Dockerfile Dockerfile.debian-${{ matrix.release }}; sed -i.bak "s/FROM.*/FROM ${ORG}\/github-runner-base:debian-${{ matrix.release }}/" Dockerfile.debian-${{ matrix.release }}
- name: Login to DockerHub
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
username: ${{ secrets.DOCKER_USER }}
password: ${{ secrets.DOCKER_TOKEN }}
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Retry build and push
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
+1 -1
View File
@@ -11,7 +11,7 @@ jobs:
stale:
runs-on: ubuntu-latest
steps:
- uses: actions/stale@v9
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0
with:
stale-issue-message: 'This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.'
stale-pr-message: 'This PR is stale because it has been open 45 days with no activity. Remove stale label or comment or this will be closed in 10 days.'
+57 -15
View File
@@ -8,11 +8,11 @@ jobs:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
- uses: actions/setup-python@v5
- uses: pre-commit/action@v3.0.1
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
- uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1
- name: Run ShellCheck
uses: ludeeus/action-shellcheck@master
uses: ludeeus/action-shellcheck@00b27aa7cb85167568cb48a3838b75f4265f2bca # master
ubuntu_tests:
runs-on: ubuntu-latest
@@ -23,13 +23,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Install Goss and dgoss
run: |
curl -fsSL https://goss.rocks/install | sh
@@ -52,7 +54,7 @@ jobs:
# Sanity check
grep FROM Dockerfile.final.ubuntu-${{ matrix.release }}
- name: Retry build final image
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -67,7 +69,7 @@ jobs:
.
# Tests will run against the final `${GH_RUNNER_IMAGE}` laid on top of `base-${GH_RUNNER_IMAGE}`
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -75,10 +77,31 @@ jobs:
echo "os: ubuntu" >goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
# test the edge case from deregistration on reusable runners
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_reusage_fail.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
-e ACCESS_TOKEN=notreal \
-e LABELS=linux,x64 \
-e REPO_URL=https://github.com/octokode/test1 \
-e RUNNER_NAME=sustainjane-runner-1 \
-e RUNNER_SCOPE=repo \
-e RUNNER_WORKDIR=/tmp/runner/work \
-e DISABLE_AUTOMATIC_DEREGISTRATION=false \
-e CONFIGURED_ACTIONS_RUNNER_FILES_DIR=/runner/data \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the base
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the final image but with all defaults
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_full_defaults.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the final image but with non-default values
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_full.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
@@ -102,7 +125,9 @@ jobs:
-e EPHEMERAL=true \
-e DISABLE_AUTO_UPDATE=true \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
debian_tests:
runs-on: ubuntu-latest
strategy:
@@ -112,13 +137,15 @@ jobs:
fail-fast: false
steps:
- name: Copy Repo Files
uses: actions/checkout@master
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5
- name: Get GitHub organization or user
run: echo 'ORG='$(echo $(dirname ${GITHUB_REPOSITORY}) | awk '{print tolower($0)}') >> $GITHUB_ENV
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
image: tonistiigi/binfmt:qemu-v7.0.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
- name: Install Goss and dgoss
run: |
curl -fsSL https://goss.rocks/install | sh
@@ -141,7 +168,7 @@ jobs:
# Sanity check
grep FROM Dockerfile.final.debian-${{ matrix.release }}
- name: Retry build final image
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -156,7 +183,7 @@ jobs:
.
# Tests will run against the final `${GH_RUNNER_IMAGE}` laid on top of `base-${GH_RUNNER_IMAGE}`
- name: Run goss tests
uses: nick-fields/retry@v3
uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2
with:
timeout_minutes: 60
max_attempts: 3
@@ -164,6 +191,21 @@ jobs:
echo "os: debian" >goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "oscodename: ${{ matrix.release }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
echo "arch: ${{ matrix.platform }}" >>goss_vars_${GH_RUNNER_IMAGE}.yaml
# test the edge case from deregistration on reusable runners
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_reusage_fail.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep \
-e DEBUG_ONLY=true \
-e ACCESS_TOKEN=notreal \
-e LABELS=linux,x64 \
-e REPO_URL=https://github.com/octokode/test1 \
-e RUNNER_NAME=sustainjane-runner-1 \
-e RUNNER_SCOPE=repo \
-e RUNNER_WORKDIR=/tmp/runner/work \
-e DISABLE_AUTOMATIC_DEREGISTRATION=false \
-e CONFIGURED_ACTIONS_RUNNER_FILES_DIR=/runner/data \
${GH_RUNNER_IMAGE} 10
if [ $? -ne 0 ]; then
exit 1
fi
# test the base
GOSS_VARS=goss_vars_${GH_RUNNER_IMAGE}.yaml GOSS_FILE=goss_base.yaml GOSS_SLEEP=1 dgoss run --entrypoint /usr/bin/sleep -e RUNNER_NAME=test -e DEBUG_ONLY=true ${GH_RUNNER_IMAGE} 10
# test the final image but with all defaults
+1 -1
View File
@@ -1 +1 @@
shellcheck 0.10.0
shellcheck 0.11.0
+1 -1
View File
@@ -5,7 +5,7 @@ LABEL maintainer="myoung34@my.apsu.edu"
ENV AGENT_TOOLSDIRECTORY=/opt/hostedtoolcache
RUN mkdir -p /opt/hostedtoolcache
ARG GH_RUNNER_VERSION="2.321.0"
ARG GH_RUNNER_VERSION="2.328.0"
ARG TARGETPLATFORM
+2 -2
View File
@@ -43,7 +43,7 @@ Currently runners [do not support containerd](https://github.com/actions/runner/
| ubuntu focal | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+/` `/\d\.\d{3}\.\d+-ubuntu-focal/`| [latest](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=latest) [ubuntu-focal](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=ubuntu-focal) | This is the latest build (Rebuilt nightly and on master merges). Tags without an OS name are included. Tags with `-ubuntu-focal` are included and created on [upstream tags](https://github.com/actions/runner/tags).|
| ubuntu noble | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-ubuntu-noble/` | [ubuntu-noble](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=ubuntu-noble) | This is the latest build from noble (Rebuilt nightly and on master merges). Tags with `-ubuntu-noble` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| ubuntu jammy | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-ubuntu-jammy/` | [ubuntu-jammy](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=ubuntu-jammy) | This is the latest build from jammy (Rebuilt nightly and on master merges). Tags with `-ubuntu-jammy` are included and created on [upstream tags](https://github.com/actions/runner/tags). | There is [currently an issue with jammy from inside a 20.04LTS host](https://github.com/myoung34/docker-github-actions-runner/issues/219) which is why this is not `latest` |
| debian buster (now deprecated) | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-debian-buster/` | [debian-buster](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-buster) | Debian buster is now deprecated. The packages for arm v7 are in flux and are wildly causing build failures (git as well as apt-key and liblttng-ust#. Tags with `-debian-buster` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| debian buster (now deprecated) | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-debian-buster/` | [debian-buster](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-buster) | Debian buster is now deprecated. The packages for arm v7 are in flux and are wildly causing build failures (git as well as liblttng-ust#. Tags with `-debian-buster` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| debian bookworm | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-debian-bookworm/` | [debian-bookworm](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-bookworm) | This is the latest build from bookworm (Rebuilt nightly and on master merges). Tags with `-debian-bookworm` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
| debian sid | `x86_64`,`arm64` | `/\d\.\d{3}\.\d+-debian-sid/` | [debian-sid](https://hub.docker.com/r/myoung34/github-runner/tags?page=1&name=debian-sid) | This is the latest build from sid (Rebuilt nightly and on master merges). Tags with `-debian-sid` are included and created on [upstream tags](https://github.com/actions/runner/tags). | |
@@ -56,7 +56,7 @@ These containers are built via Github actions that [copy the dockerfile](https:/
| `RUN_AS_ROOT` | Boolean to run as root. If `true`: will run as root. If `True` and the user is overridden it will error. If any other value it will run as the `runner` user and allow an optional override. Default is `true` |
| `RUNNER_NAME` | The name of the runner to use. Supersedes (overrides) `RUNNER_NAME_PREFIX` |
| `RUNNER_NAME_PREFIX` | A prefix for runner name (See `RANDOM_RUNNER_SUFFIX` for how the full name is generated). Note: will be overridden by `RUNNER_NAME` if provided. Defaults to `github-runner` |
| `RANDOM_RUNNER_SUFFIX` | Boolean to use a randomized runner name suffix (preceded by `RUNNER_NAME_PREFIX`). Will use a 13 character random string by default. If set to a value other than true it will attempt to use the contents of `/etc/hostname` or fall back to a random string if the file does not exist or is empty. Note: will be overridden by `RUNNER_NAME` if provided. Defaults to `true`. |
| `RANDOM_RUNNER_SUFFIX` | Boolean to use a randomized runner name suffix (preceded by `RUNNER_NAME_PREFIX`). Will use a 13 character random string by default. If set to a value other than true and `RUNNER_NAME_PREFIX` is set to an empty string, it will attempt to use the contents of `/etc/hostname` or fall back to a random string if the file does not exist or is empty. Note: will be overridden by `RUNNER_NAME` if provided. Defaults to `true`. |
| `ACCESS_TOKEN` | A [github PAT](https://docs.github.com/en/github/authenticating-to-github/creating-a-personal-access-token) to use to generate `RUNNER_TOKEN` dynamically at container start. Not using this requires a valid `RUNNER_TOKEN` |
| `APP_ID` | The github application ID. Must be paired with `APP_PRIVATE_KEY` and should not be used with `ACCESS_TOKEN` or `RUNNER_TOKEN` |
| `APP_PRIVATE_KEY` | The github application private key. Must be paired with `APP_ID` and should not be used with `ACCESS_TOKEN` or `RUNNER_TOKEN` |
+2 -1
View File
@@ -17,7 +17,8 @@ function install_essentials() {
locales \
gosu \
gpg-agent \
dumb-init
dumb-init \
libc-bin
}
function install_tools_apt() {
+10 -5
View File
@@ -6,12 +6,17 @@ function configure_git() {
source /etc/os-release
local GIT_CORE_PPA_KEY="A1715D88E1DF1F24"
apt-key adv --keyserver keyserver.ubuntu.com --recv-keys ${GIT_CORE_PPA_KEY} \
|| apt-key adv --keyserver pgp.mit.edu --recv-keys ${GIT_CORE_PPA_KEY} \
|| apt-key adv --keyserver keyserver.pgp.com --recv-keys ${GIT_CORE_PPA_KEY}
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys ${GIT_CORE_PPA_KEY}
gpg --export ${GIT_CORE_PPA_KEY} | gpg --dearmor -o /usr/share/keyrings/git-core.gpg
if [[ "${VERSION_CODENAME}" == "focal" ]]; then
echo deb http://ppa.launchpad.net/git-core/ppa/ubuntu focal main>/etc/apt/sources.list.d/git-core.list
local GIT_CORE_FOCAL_PPA_KEY="E363C90F8F1B6217"
local KEYRING_FILE="/usr/share/keyrings/git-core-focal.gpg"
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys ${GIT_CORE_FOCAL_PPA_KEY}
gpg --export ${GIT_CORE_FOCAL_PPA_KEY} | gpg --dearmor -o "${KEYRING_FILE}"
echo deb [signed-by=${KEYRING_FILE}] http://ppa.launchpad.net/git-core/ppa/ubuntu focal main>/etc/apt/sources.list.d/git-core.list
fi
}
@@ -38,7 +43,7 @@ function configure_container_tools() {
echo "deb https://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_20.04/ /" \
| tee /etc/apt/sources.list.d/devel:kubic:libcontainers:stable.list
curl -L "https://build.opensuse.org/projects/devel:kubic/signing_keys/download?kind=gpg" \
| apt-key add -
| /usr/bin/apt-key add -
fi
}
+7 -2
View File
@@ -42,7 +42,8 @@ if [[ ${RANDOM_RUNNER_SUFFIX} != "true" ]]; then
if [[ -f "/etc/hostname" ]]; then
# in some cases it can also be empty
if [[ $(stat --printf="%s" /etc/hostname) -ne 0 ]]; then
_RUNNER_NAME=${RUNNER_NAME:-${RUNNER_NAME_PREFIX:-github-runner}-$(cat /etc/hostname)}
_RUNNER_NAME_PREFIX=${RUNNER_NAME_PREFIX-"github-runner"}
_RUNNER_NAME=${RUNNER_NAME:-${_RUNNER_NAME_PREFIX:+${_RUNNER_NAME_PREFIX}-}$(cat /etc/hostname)}
echo "RANDOM_RUNNER_SUFFIX is ${RANDOM_RUNNER_SUFFIX}. /etc/hostname exists and has content. Setting runner name to ${_RUNNER_NAME}"
else
echo "RANDOM_RUNNER_SUFFIX is ${RANDOM_RUNNER_SUFFIX} ./etc/hostname exists but is empty. Not using /etc/hostname."
@@ -150,7 +151,7 @@ configure_runner() {
--replace \
"${ARGS[@]}"
[[ ! -d "${_RUNNER_WORKDIR}" ]] && mkdir "${_RUNNER_WORKDIR}"
[[ ! -d "${_RUNNER_WORKDIR}" ]] && mkdir -p "${_RUNNER_WORKDIR}"
}
@@ -210,6 +211,10 @@ fi
if [[ -n "${_CONFIGURED_ACTIONS_RUNNER_FILES_DIR}" ]]; then
echo "Reusage is enabled. Storing data to ${_CONFIGURED_ACTIONS_RUNNER_FILES_DIR}"
if [[ ${_DISABLE_AUTOMATIC_DEREGISTRATION} == "false" ]]; then
echo "DISABLE_AUTOMATIC_DEREGISTRATION should be set to true to avoid issues with re-using a deregistered runner."
exit 1
fi
# Quoting (even with double-quotes) the regexp brokes the copying
cp -p -r "/actions-runner/_diag" "/actions-runner/svc.sh" /actions-runner/.[^.]* "${_CONFIGURED_ACTIONS_RUNNER_FILES_DIR}"
fi
+9
View File
@@ -0,0 +1,9 @@
command:
/entrypoint.sh something:
exit-status: 1
stdout:
- "Runner reusage is enabled"
- "Reusage is enabled. Storing data to /runner/data"
- "DISABLE_AUTOMATIC_DEREGISTRATION should be set to true to avoid issues with re-using a deregistered runner."
stderr: ""
timeout: 2000
+1 -1
View File
@@ -10,4 +10,4 @@ curl -L "https://github.com/actions/runner/releases/download/v${GH_RUNNER_VERSIO
tar -zxf actions.tar.gz
rm -f actions.tar.gz
./bin/installdependencies.sh
mkdir /_work
mkdir -p /_work
+7 -1
View File
@@ -1,7 +1,8 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:base"
"config:base",
"helpers:pinGitHubActionDigests"
],
"packageRules": [
{
@@ -11,6 +12,11 @@
{
"matchDepTypes": ["devDependencies"],
"automerge": true
},
{
"matchManagers": ["github-actions"],
"matchPackagePatterns": [".*"],
"versioning": "digest"
}
],
"platformAutomerge": true