Skip to content

Merge pull request #1575 from finos/dependabot/npm_and_yarn/uuid-14.0.0 #116

Merge pull request #1575 from finos/dependabot/npm_and_yarn/uuid-14.0.0

Merge pull request #1575 from finos/dependabot/npm_and_yarn/uuid-14.0.0 #116

name: Build and Publish Docker Image
on:
push:
branches: [main]
release:
types: [published]
permissions:
contents: read
jobs:
docker-build-publish:
permissions:
contents: read
name: Build and Publish Docker Image
runs-on: ubuntu-latest
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4
- name: Checkout Repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- name: Log in to Docker Hub
if: github.repository_owner == 'finos'
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4
with:
username: finos
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Set Docker Image Tag
id: tags
run: |
if [ "${{ github.event_name }}" = "release" ]; then
echo "tags=${{ github.repository }}:${{ github.ref_name }},${{ github.repository }}:latest" >> $GITHUB_OUTPUT
else
echo "tags=${{ github.repository }}:main" >> $GITHUB_OUTPUT
fi
- name: Build and Publish Docker Image
if: github.repository_owner == 'finos'
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7
with:
context: .
file: Dockerfile
push: true
tags: ${{ steps.tags.outputs.tags }}
provenance: true