release.yml 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657
  1. name: Create and publish a Docker image
  2. on:
  3. release:
  4. types: [published]
  5. env:
  6. REGISTRY: ghcr.io
  7. IMAGE_NAME: ${{ github.repository }}
  8. jobs:
  9. build-and-push-image:
  10. runs-on: ubuntu-latest
  11. permissions:
  12. contents: read
  13. packages: write
  14. steps:
  15. - name: Checkout repository
  16. uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
  17. - name: Set up QEMU
  18. uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0
  19. - name: Set up Docker Buildx
  20. id: buildx
  21. uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
  22. - name: Log in to Docker Hub
  23. uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
  24. with:
  25. username: ${{ github.actor }}
  26. password: ${{ secrets.DOCKER_PASSWORD }}
  27. - name: Log in to the Container registry
  28. uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
  29. with:
  30. registry: ${{ env.REGISTRY }}
  31. username: ${{ github.actor }}
  32. password: ${{ secrets.GITHUB_TOKEN }}
  33. - name: Extract metadata (tags, labels) for Docker
  34. id: meta
  35. uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
  36. with:
  37. images: |
  38. zricethezav/gitleaks
  39. ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
  40. - name: Build and push Docker image
  41. uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
  42. with:
  43. platforms: linux/amd64,linux/arm64
  44. context: .
  45. push: true
  46. tags: ${{ steps.meta.outputs.tags }}
  47. labels: ${{ steps.meta.outputs.labels }}