mirror of
https://github.com/anchore/syft.git
synced 2026-08-19 08:38:25 +02:00
chore: migrate .goreleaser config to use docker_v2 (#4608)
--------- Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
This commit is contained in:
parent
ad828d659f
commit
ed499fd2d0
9
.github/workflows/release.yaml
vendored
9
.github/workflows/release.yaml
vendored
@ -63,8 +63,13 @@ jobs:
|
|||||||
# spot disabled: reliability for build workflows (used for releases too)
|
# spot disabled: reliability for build workflows (used for releases too)
|
||||||
# goreleaser uses parallelism of 12, so we need more CPUs
|
# goreleaser uses parallelism of 12, so we need more CPUs
|
||||||
# s3-cache: faster actions cache
|
# s3-cache: faster actions cache
|
||||||
# tmpfs: faster io-intensive workflows
|
# volume: enlarge dist/ disk -- the default 40GB EBS root fills up during the multi-arch
|
||||||
runs-on: runs-on=${{ github.run_id }}/cpu=16+32/ram=32+128/family=c5+c6+c7+c8/spot=false/extras=s3-cache+tmpfs
|
# image + binary build and OOMs (runs out of disk); size it well above peak usage.
|
||||||
|
# provisioned throughput/iops above the gp3 free baseline (125mbs/3000iops) approximate
|
||||||
|
# the tmpfs IO speed on disk, for ~1c/run.
|
||||||
|
# note: tmpfs intentionally omitted -- a RAM-backed dist/ never touches the enlarged
|
||||||
|
# volume and competes with the build's memory peak, so keep dist/ on disk.
|
||||||
|
runs-on: runs-on=${{ github.run_id }}/cpu=16+32/ram=32+128/family=c5+c6+c7+c8/spot=false/extras=s3-cache/volume=120gb:gp3:500mbs:4000iops
|
||||||
permissions:
|
permissions:
|
||||||
contents: write # required for creating the GitHub release and pushing the version tag
|
contents: write # required for creating the GitHub release and pushing the version tag
|
||||||
packages: write # required for publishing release artifacts to GitHub packages
|
packages: write # required for publishing release artifacts to GitHub packages
|
||||||
|
|||||||
10
.github/workflows/validations.yaml
vendored
10
.github/workflows/validations.yaml
vendored
@ -92,10 +92,16 @@ jobs:
|
|||||||
# runs-on.com: compute instances for parallel builds
|
# runs-on.com: compute instances for parallel builds
|
||||||
# spot disabled: reliability for build workflows (used for releases too)
|
# spot disabled: reliability for build workflows (used for releases too)
|
||||||
# goreleaser uses parallelism of 12, so we need more CPUs
|
# goreleaser uses parallelism of 12, so we need more CPUs
|
||||||
# tmpfs: faster io-intensive workflows
|
# tmpfs intentionally omitted -- a RAM-backed dist/ competes with the goreleaser
|
||||||
|
# build's memory peak (parallel binaries + multi-arch image assembly) and OOMs the
|
||||||
|
# instance; keep dist/ on disk.
|
||||||
# note: s3-cache intentionally omitted -- PR runs are untrusted and must not write to the
|
# note: s3-cache intentionally omitted -- PR runs are untrusted and must not write to the
|
||||||
# shared cache backend that the trusted release workflow reads from (cache poisoning).
|
# shared cache backend that the trusted release workflow reads from (cache poisoning).
|
||||||
runs-on: "runs-on=${{ github.run_id }}/cpu=16+32/ram=32+128/family=c5+c6+c7+c8/spot=false/extras=tmpfs"
|
# volume: enlarge dist/ disk -- the default 40GB EBS root fills up during the multi-arch
|
||||||
|
# image + binary build and OOMs (runs out of disk); size it well above peak usage.
|
||||||
|
# provisioned throughput/iops above the gp3 free baseline (125mbs/3000iops) approximate
|
||||||
|
# the tmpfs IO speed on disk, for ~1c/run.
|
||||||
|
runs-on: "runs-on=${{ github.run_id }}/cpu=16+32/ram=32+128/family=c5+c6+c7+c8/spot=false/volume=120gb:gp3:500mbs:4000iops"
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
steps:
|
steps:
|
||||||
|
|||||||
370
.goreleaser.yaml
370
.goreleaser.yaml
@ -73,306 +73,88 @@ brews:
|
|||||||
description: *description
|
description: *description
|
||||||
license: "Apache License 2.0"
|
license: "Apache License 2.0"
|
||||||
|
|
||||||
dockers:
|
dockers_v2:
|
||||||
# production images...
|
# production images (scratch base, root)
|
||||||
- image_templates:
|
- id: production
|
||||||
- anchore/syft:{{.Tag}}-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-amd64
|
|
||||||
goarch: amd64
|
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
use: buildx
|
ids: &docker-ids
|
||||||
build_flag_templates:
|
- linux-build
|
||||||
- "--platform=linux/amd64"
|
images: &docker-images
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
- anchore/syft
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
- ghcr.io/anchore/syft
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
platforms: &docker-platforms
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
- linux/amd64
|
||||||
|
- linux/arm64
|
||||||
|
- linux/ppc64le
|
||||||
|
- linux/riscv64
|
||||||
|
- linux/s390x
|
||||||
|
labels: &docker-labels
|
||||||
|
"org.opencontainers.image.created": "{{.Date}}"
|
||||||
|
"org.opencontainers.image.title": "syft"
|
||||||
|
"org.opencontainers.image.description": "CLI tool and library for generating a Software Bill of Materials from container images and filesystems"
|
||||||
|
"org.opencontainers.image.source": "{{.GitURL}}"
|
||||||
|
"org.opencontainers.image.revision": "{{.FullCommit}}"
|
||||||
|
"org.opencontainers.image.vendor": "Anchore, Inc."
|
||||||
|
"org.opencontainers.image.version": "{{.Version}}"
|
||||||
|
"org.opencontainers.image.licenses": "Apache-2.0"
|
||||||
|
"io.artifacthub.package.readme-url": "https://raw.githubusercontent.com/anchore/syft/main/README.md"
|
||||||
|
"io.artifacthub.package.logo-url": "https://user-images.githubusercontent.com/5199289/136844524-1527b09f-c5cb-4aa9-be54-5aa92a6086c1.png"
|
||||||
|
"io.artifacthub.package.license": "Apache-2.0"
|
||||||
|
tags:
|
||||||
|
- latest
|
||||||
|
- "{{.Tag}}"
|
||||||
|
# DEBIAN_VERSION 13 (trixie) is the first distroless release with a riscv64 base image
|
||||||
|
# and is a superset of debian 12 for the other targeted arches; docker_v2 builds all
|
||||||
|
# platforms in a single buildx invocation, so build_args cannot vary per platform.
|
||||||
|
build_args: &docker-build-args
|
||||||
|
DEBIAN_VERSION: "13"
|
||||||
|
# disable provenance attestations to keep the manifest free of unknown/unknown entries
|
||||||
|
flags: &docker-flags
|
||||||
|
- "--provenance=false"
|
||||||
|
# SBOMs are produced separately for the archives (see the sboms section)
|
||||||
|
sbom: &docker-sbom "false"
|
||||||
|
|
||||||
- image_templates:
|
# nonroot images
|
||||||
- anchore/syft:{{.Tag}}-arm64v8
|
- id: nonroot
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-arm64v8
|
|
||||||
goarch: arm64
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/arm64/v8"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
goarch: ppc64le
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/ppc64le"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-riscv64
|
|
||||||
goarch: riscv64
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/riscv64"
|
|
||||||
- "--build-arg=DEBIAN_VERSION=13"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-s390x
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-s390x
|
|
||||||
goarch: s390x
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/s390x"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
# nonroot images...
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
goarch: amd64
|
|
||||||
dockerfile: Dockerfile.nonroot
|
dockerfile: Dockerfile.nonroot
|
||||||
use: buildx
|
ids: *docker-ids
|
||||||
build_flag_templates:
|
images: *docker-images
|
||||||
- "--platform=linux/amd64"
|
platforms: *docker-platforms
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
labels: *docker-labels
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
tags:
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
- nonroot
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
- "{{.Tag}}-nonroot"
|
||||||
|
build_args: *docker-build-args
|
||||||
|
flags: *docker-flags
|
||||||
|
sbom: *docker-sbom
|
||||||
|
|
||||||
- image_templates:
|
# debug images (root)
|
||||||
- anchore/syft:{{.Tag}}-nonroot-arm64v8
|
- id: debug
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-arm64v8
|
|
||||||
goarch: arm64
|
|
||||||
dockerfile: Dockerfile.nonroot
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/arm64/v8"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
goarch: ppc64le
|
|
||||||
dockerfile: Dockerfile.nonroot
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/ppc64le"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
goarch: riscv64
|
|
||||||
dockerfile: Dockerfile.nonroot
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/riscv64"
|
|
||||||
- "--build-arg=DEBIAN_VERSION=13"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
goarch: s390x
|
|
||||||
dockerfile: Dockerfile.nonroot
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/s390x"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
# debug images...
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
goarch: amd64
|
|
||||||
dockerfile: Dockerfile.debug
|
dockerfile: Dockerfile.debug
|
||||||
use: buildx
|
ids: *docker-ids
|
||||||
build_flag_templates:
|
images: *docker-images
|
||||||
- "--platform=linux/amd64"
|
platforms: *docker-platforms
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
labels: *docker-labels
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
tags:
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
- debug
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
- "{{.Tag}}-debug"
|
||||||
|
build_args: *docker-build-args
|
||||||
|
flags: *docker-flags
|
||||||
|
sbom: *docker-sbom
|
||||||
|
|
||||||
- image_templates:
|
# debug-nonroot images
|
||||||
- anchore/syft:{{.Tag}}-debug-arm64v8
|
- id: debug-nonroot
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-arm64v8
|
dockerfile: Dockerfile.debug-nonroot
|
||||||
goarch: arm64
|
ids: *docker-ids
|
||||||
dockerfile: Dockerfile.debug
|
images: *docker-images
|
||||||
use: buildx
|
platforms: *docker-platforms
|
||||||
build_flag_templates:
|
labels: *docker-labels
|
||||||
- "--platform=linux/arm64/v8"
|
tags:
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
- debug-nonroot
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
- "{{.Tag}}-debug-nonroot"
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
build_args: *docker-build-args
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
flags: *docker-flags
|
||||||
|
sbom: *docker-sbom
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
goarch: ppc64le
|
|
||||||
dockerfile: Dockerfile.debug
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/ppc64le"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
goarch: riscv64
|
|
||||||
dockerfile: Dockerfile.debug
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/riscv64"
|
|
||||||
- "--build-arg=DEBIAN_VERSION=13"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
- image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
goarch: s390x
|
|
||||||
dockerfile: Dockerfile.debug
|
|
||||||
use: buildx
|
|
||||||
build_flag_templates:
|
|
||||||
- "--platform=linux/s390x"
|
|
||||||
- "--build-arg=BUILD_DATE={{.Date}}"
|
|
||||||
- "--build-arg=BUILD_VERSION={{.Version}}"
|
|
||||||
- "--build-arg=VCS_REF={{.FullCommit}}"
|
|
||||||
- "--build-arg=VCS_URL={{.GitURL}}"
|
|
||||||
|
|
||||||
docker_manifests:
|
|
||||||
- name_template: anchore/syft:latest
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:latest
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-s390x
|
|
||||||
|
|
||||||
- name_template: anchore/syft:{{.Tag}}
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:{{.Tag}}
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-s390x
|
|
||||||
|
|
||||||
# nonroot images...
|
|
||||||
- name_template: anchore/syft:nonroot
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:nonroot
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
|
|
||||||
- name_template: anchore/syft:{{.Tag}}-nonroot
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:{{.Tag}}-nonroot
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-nonroot-s390x
|
|
||||||
|
|
||||||
# debug images...
|
|
||||||
- name_template: anchore/syft:debug
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-debug-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:debug
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
|
|
||||||
- name_template: anchore/syft:{{.Tag}}-debug
|
|
||||||
image_templates:
|
|
||||||
- anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
- anchore/syft:{{.Tag}}-debug-arm64v8
|
|
||||||
- anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
- anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
- anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
|
|
||||||
- name_template: ghcr.io/anchore/syft:{{.Tag}}-debug
|
|
||||||
image_templates:
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-amd64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-arm64v8
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-ppc64le
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-riscv64
|
|
||||||
- ghcr.io/anchore/syft:{{.Tag}}-debug-s390x
|
|
||||||
|
|
||||||
sboms:
|
sboms:
|
||||||
- artifacts: archive
|
- artifacts: archive
|
||||||
|
|||||||
22
Dockerfile
22
Dockerfile
@ -1,4 +1,4 @@
|
|||||||
ARG DEBIAN_VERSION=12
|
ARG DEBIAN_VERSION=13
|
||||||
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:latest AS build
|
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:latest AS build
|
||||||
|
|
||||||
FROM scratch
|
FROM scratch
|
||||||
@ -8,23 +8,7 @@ COPY --from=build /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certifica
|
|||||||
# create the /tmp dir, which is needed for image content cache
|
# create the /tmp dir, which is needed for image content cache
|
||||||
WORKDIR /tmp
|
WORKDIR /tmp
|
||||||
|
|
||||||
COPY syft /
|
ARG TARGETPLATFORM
|
||||||
|
COPY ${TARGETPLATFORM}/syft /
|
||||||
ARG BUILD_DATE
|
|
||||||
ARG BUILD_VERSION
|
|
||||||
ARG VCS_REF
|
|
||||||
ARG VCS_URL
|
|
||||||
|
|
||||||
LABEL org.opencontainers.image.created=$BUILD_DATE
|
|
||||||
LABEL org.opencontainers.image.title="syft"
|
|
||||||
LABEL org.opencontainers.image.description="CLI tool and library for generating a Software Bill of Materials from container images and filesystems"
|
|
||||||
LABEL org.opencontainers.image.source=$VCS_URL
|
|
||||||
LABEL org.opencontainers.image.revision=$VCS_REF
|
|
||||||
LABEL org.opencontainers.image.vendor="Anchore, Inc."
|
|
||||||
LABEL org.opencontainers.image.version=$BUILD_VERSION
|
|
||||||
LABEL org.opencontainers.image.licenses="Apache-2.0"
|
|
||||||
LABEL io.artifacthub.package.readme-url="https://raw.githubusercontent.com/anchore/syft/main/README.md"
|
|
||||||
LABEL io.artifacthub.package.logo-url="https://user-images.githubusercontent.com/5199289/136844524-1527b09f-c5cb-4aa9-be54-5aa92a6086c1.png"
|
|
||||||
LABEL io.artifacthub.package.license="Apache-2.0"
|
|
||||||
|
|
||||||
ENTRYPOINT ["/syft"]
|
ENTRYPOINT ["/syft"]
|
||||||
|
|||||||
@ -1,28 +1,10 @@
|
|||||||
ARG DEBIAN_VERSION=12
|
ARG DEBIAN_VERSION=13
|
||||||
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:debug-nonroot
|
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:debug
|
||||||
|
|
||||||
# create the /tmp dir, which is needed for image content cache
|
# create the /tmp dir, which is needed for image content cache
|
||||||
WORKDIR /tmp
|
WORKDIR /tmp
|
||||||
|
|
||||||
COPY syft /
|
ARG TARGETPLATFORM
|
||||||
|
COPY ${TARGETPLATFORM}/syft /
|
||||||
USER nonroot
|
|
||||||
|
|
||||||
ARG BUILD_DATE
|
|
||||||
ARG BUILD_VERSION
|
|
||||||
ARG VCS_REF
|
|
||||||
ARG VCS_URL
|
|
||||||
|
|
||||||
LABEL org.opencontainers.image.created=$BUILD_DATE
|
|
||||||
LABEL org.opencontainers.image.title="syft"
|
|
||||||
LABEL org.opencontainers.image.description="CLI tool and library for generating a Software Bill of Materials from container images and filesystems"
|
|
||||||
LABEL org.opencontainers.image.source=$VCS_URL
|
|
||||||
LABEL org.opencontainers.image.revision=$VCS_REF
|
|
||||||
LABEL org.opencontainers.image.vendor="Anchore, Inc."
|
|
||||||
LABEL org.opencontainers.image.version=$BUILD_VERSION
|
|
||||||
LABEL org.opencontainers.image.licenses="Apache-2.0"
|
|
||||||
LABEL io.artifacthub.package.readme-url="https://raw.githubusercontent.com/anchore/syft/main/README.md"
|
|
||||||
LABEL io.artifacthub.package.logo-url="https://user-images.githubusercontent.com/5199289/136844524-1527b09f-c5cb-4aa9-be54-5aa92a6086c1.png"
|
|
||||||
LABEL io.artifacthub.package.license="Apache-2.0"
|
|
||||||
|
|
||||||
ENTRYPOINT ["/syft"]
|
ENTRYPOINT ["/syft"]
|
||||||
|
|||||||
12
Dockerfile.debug-nonroot
Normal file
12
Dockerfile.debug-nonroot
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
ARG DEBIAN_VERSION=13
|
||||||
|
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:debug-nonroot
|
||||||
|
|
||||||
|
# create the /tmp dir, which is needed for image content cache
|
||||||
|
WORKDIR /tmp
|
||||||
|
|
||||||
|
ARG TARGETPLATFORM
|
||||||
|
COPY ${TARGETPLATFORM}/syft /
|
||||||
|
|
||||||
|
USER nonroot
|
||||||
|
|
||||||
|
ENTRYPOINT ["/syft"]
|
||||||
@ -1,28 +1,12 @@
|
|||||||
ARG DEBIAN_VERSION=12
|
ARG DEBIAN_VERSION=13
|
||||||
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:nonroot
|
FROM gcr.io/distroless/static-debian${DEBIAN_VERSION}:nonroot
|
||||||
|
|
||||||
# create the /tmp dir, which is needed for image content cache
|
# create the /tmp dir, which is needed for image content cache
|
||||||
WORKDIR /tmp
|
WORKDIR /tmp
|
||||||
|
|
||||||
COPY syft /
|
ARG TARGETPLATFORM
|
||||||
|
COPY ${TARGETPLATFORM}/syft /
|
||||||
|
|
||||||
USER nonroot
|
USER nonroot
|
||||||
|
|
||||||
ARG BUILD_DATE
|
|
||||||
ARG BUILD_VERSION
|
|
||||||
ARG VCS_REF
|
|
||||||
ARG VCS_URL
|
|
||||||
|
|
||||||
LABEL org.opencontainers.image.created=$BUILD_DATE
|
|
||||||
LABEL org.opencontainers.image.title="syft"
|
|
||||||
LABEL org.opencontainers.image.description="CLI tool and library for generating a Software Bill of Materials from container images and filesystems"
|
|
||||||
LABEL org.opencontainers.image.source=$VCS_URL
|
|
||||||
LABEL org.opencontainers.image.revision=$VCS_REF
|
|
||||||
LABEL org.opencontainers.image.vendor="Anchore, Inc."
|
|
||||||
LABEL org.opencontainers.image.version=$BUILD_VERSION
|
|
||||||
LABEL org.opencontainers.image.licenses="Apache-2.0"
|
|
||||||
LABEL io.artifacthub.package.readme-url="https://raw.githubusercontent.com/anchore/syft/main/README.md"
|
|
||||||
LABEL io.artifacthub.package.logo-url="https://user-images.githubusercontent.com/5199289/136844524-1527b09f-c5cb-4aa9-be54-5aa92a6086c1.png"
|
|
||||||
LABEL io.artifacthub.package.license="Apache-2.0"
|
|
||||||
|
|
||||||
ENTRYPOINT ["/syft"]
|
ENTRYPOINT ["/syft"]
|
||||||
|
|||||||
@ -39,6 +39,12 @@ vars:
|
|||||||
PROJECT_ROOT:
|
PROJECT_ROOT:
|
||||||
sh: echo $PWD
|
sh: echo $PWD
|
||||||
|
|
||||||
|
# docker platform suffix goreleaser appends to snapshot image tags (e.g. latest-amd64).
|
||||||
|
# snapshot builds load per-arch images rather than a multi-arch manifest, so the smoke
|
||||||
|
# test must run the host-native tag to avoid emulation (and red-local/green-CI splits).
|
||||||
|
DOCKER_ARCH:
|
||||||
|
sh: go env GOARCH
|
||||||
|
|
||||||
# note: the snapshot dir must be a relative path starting with ./
|
# note: the snapshot dir must be a relative path starting with ./
|
||||||
# e.g. when installing snapshot debs from a local path, ./ forces the deb to be installed in the current working directory instead of referencing a package name
|
# e.g. when installing snapshot debs from a local path, ./ forces the deb to be installed in the current working directory instead of referencing a package name
|
||||||
SNAPSHOT_DIR: ./snapshot
|
SNAPSHOT_DIR: ./snapshot
|
||||||
@ -129,8 +135,8 @@ tasks:
|
|||||||
silent: true
|
silent: true
|
||||||
- "{{ .SNAPSHOT_BIN }} version"
|
- "{{ .SNAPSHOT_BIN }} version"
|
||||||
- "{{ .SNAPSHOT_BIN }} scan alpine:latest"
|
- "{{ .SNAPSHOT_BIN }} scan alpine:latest"
|
||||||
- docker run --rm anchore/syft:latest version
|
- docker run --pull=never --rm anchore/syft:latest-{{ .DOCKER_ARCH }} version
|
||||||
- docker run --rm anchore/syft:latest scan alpine:latest
|
- docker run --pull=never --rm anchore/syft:latest-{{ .DOCKER_ARCH }} scan alpine:latest
|
||||||
|
|
||||||
## Test-fixture-related targets ###########################################
|
## Test-fixture-related targets ###########################################
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user