Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] Tag images with commit hash #134

Closed
p5 opened this issue Aug 9, 2024 · 0 comments · Fixed by #136
Closed

[FR] Tag images with commit hash #134

p5 opened this issue Aug 9, 2024 · 0 comments · Fixed by #136
Labels
enhancement New feature or request help wanted Extra attention is needed

Comments

@p5
Copy link

p5 commented Aug 9, 2024

Is your feature request related to a problem? Please describe.

It's a security best practice to pin your GitHub Action versions to a particular commit hash to prevent changes happening without your knowledge. This helps improve supply chain security.

This results in workflows calling jasonn3/build-container-installer@ceccfc98ef73825152095431bfa85c796f174c7a rather than jasonn3/build-container-installer@v1.2.2.

During the build, GitHub Actions tries to lookup the Docker image tagged with ceccfc98ef73825152095431bfa85c796f174c7a due to the ${{ github.action_ref }} context, which fails because there are no images being tagged with this.
(example build log)

Describe the solution you'd like

It would be great if the images could be tagged with both the version number and commit hash to help improve the security of the supply chain, and allow others to follow best practice.

@p5 p5 added enhancement New feature or request help wanted Extra attention is needed labels Aug 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed
Projects
None yet
1 participant