From 17bdcf9c78be51991a506f767c9c7c4116e46d95 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Fri, 11 Jul 2025 13:43:27 +0200 Subject: [PATCH] Fix SBOM for docker image Signed-off-by: Bryan Frimin --- .github/workflows/release.yaml | 49 +++------------------------------- .goreleaser.yaml | 16 +++++------ 2 files changed, 12 insertions(+), 53 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 7771531f1..71ebadace 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -98,51 +98,10 @@ jobs: - name: Get image digest id: image run: | - # Wait for the multi-platform manifest to be available - echo "Waiting for multi-platform manifest to be available..." - for i in {1..30}; do - echo "Attempt $i/30: Checking if image is available..." - - # Try to get the digest from the registry - DIGEST=$(docker buildx imagetools inspect ghcr.io/getprobo/probo:${{ github.ref_name }} --format '{{.Descriptor.Digest}}' 2>/dev/null || echo "") - - if [ -n "$DIGEST" ]; then - echo "Successfully retrieved digest: $DIGEST" - echo "digest=$DIGEST" >> "$GITHUB_OUTPUT" - exit 0 - fi - - echo "Image not available yet, waiting 10 seconds..." - sleep 10 - done - - # If we get here, the primary method failed, try alternative approaches - echo "Primary method failed, trying alternative methods..." - - # Try inspecting the latest tag - echo "Trying latest tag..." - DIGEST=$(docker buildx imagetools inspect ghcr.io/getprobo/probo:latest --format '{{.Descriptor.Digest}}' 2>/dev/null || echo "") - - if [ -n "$DIGEST" ]; then - echo "Successfully retrieved digest from latest tag: $DIGEST" - echo "digest=$DIGEST" >> "$GITHUB_OUTPUT" - exit 0 - fi - - # Try getting digest from individual architecture images - echo "Trying to get digest from amd64 image..." - DIGEST_AMD64=$(docker buildx imagetools inspect ghcr.io/getprobo/probo:${{ github.ref_name }}-amd64 --format '{{.Descriptor.Digest}}' 2>/dev/null || echo "") - - if [ -n "$DIGEST_AMD64" ]; then - echo "Using amd64 image digest: $DIGEST_AMD64" - echo "digest=$DIGEST_AMD64" >> "$GITHUB_OUTPUT" - exit 0 - fi - - echo "Error: Could not retrieve image digest from registry after all attempts" - echo "Available tags for debugging:" - docker buildx imagetools inspect ghcr.io/getprobo/probo --format '{{json .}}' 2>/dev/null || echo "Failed to inspect repository" - exit 1 + echo "Getting image digest..." + DIGEST=$(docker buildx imagetools inspect ghcr.io/getprobo/probo:${{ github.ref_name }} --format '{{.Manifest.Digest}}') + echo "Successfully retrieved digest: $DIGEST" + echo "digest=$DIGEST" >> "$GITHUB_OUTPUT" - name: Attest Docker image SBOM uses: actions/attest-sbom@v1 diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 3465d7c6f..f99c4806f 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -88,10 +88,10 @@ signs: output: true docker_manifests: - - name_template: "ghcr.io/getprobo/probo:{{ .Version }}" + - name_template: "ghcr.io/getprobo/probo:{{ .Tag }}" image_templates: - - "ghcr.io/getprobo/probo:{{ .Version }}-amd64" - - "ghcr.io/getprobo/probo:{{ .Version }}-arm64" + - "ghcr.io/getprobo/probo:{{ .Tag }}-amd64" + - "ghcr.io/getprobo/probo:{{ .Tag }}-arm64" skip_push: "{{ .IsSnapshot }}" - name_template: "ghcr.io/getprobo/probo:latest" image_templates: @@ -123,7 +123,7 @@ docker_signs: dockers: - image_templates: - - "ghcr.io/getprobo/probo:{{ .Version }}-amd64" + - "ghcr.io/getprobo/probo:{{ .Tag }}-amd64" - "ghcr.io/getprobo/probo:latest-amd64" dockerfile: Dockerfile use: buildx @@ -144,7 +144,7 @@ dockers: goarch: amd64 skip_push: "{{ .IsSnapshot }}" - image_templates: - - "ghcr.io/getprobo/probo:{{ .Version }}-arm64" + - "ghcr.io/getprobo/probo:{{ .Tag }}-arm64" - "ghcr.io/getprobo/probo:latest-arm64" dockerfile: Dockerfile use: buildx @@ -188,9 +188,9 @@ release: ## Changes in {{ .Tag }} footer: | ## Docker Images - - `ghcr.io/getprobo/probo:{{ .Version }}` (multi-arch: linux/amd64, linux/arm64) + - `ghcr.io/getprobo/probo:{{ .Tag }}` (multi-arch: linux/amd64, linux/arm64) - `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64) ### Architecture-specific images - - `ghcr.io/getprobo/probo:{{ .Version }}-amd64` - - `ghcr.io/getprobo/probo:{{ .Version }}-arm64` + - `ghcr.io/getprobo/probo:{{ .Tag }}-amd64` + - `ghcr.io/getprobo/probo:{{ .Tag }}-arm64`