fix gitea backend: use full GitHub URLs for all action refs
Some checks failed
Deploy / report-vulns (push) Has been skipped
CI / lint-test (push) Failing after 28s
Deploy / build (push) Failing after 1m54s
Deploy / scan (push) Has been skipped

Gitea Actions resolves short refs (e.g. actions/checkout@v4)
against the local Gitea instance, failing with "user redirect
does not exist". All action uses: now use full URLs:
  https://github.com/actions/checkout@v4
  https://github.com/astral-sh/setup-uv@v4
  https://github.com/docker/build-push-action@v6
  etc.
This commit is contained in:
kert
2026-03-23 21:33:32 -04:00
parent f6420d60e1
commit 1c381360fd
7 changed files with 173 additions and 90 deletions

View File

@@ -13,10 +13,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
uses: astral-sh/setup-uv@v4 uses: https://github.com/astral-sh/setup-uv@v4
with: with:
version: latest version: latest

View File

@@ -12,13 +12,13 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Log in to container registry - name: Log in to container registry
uses: docker/login-action@v3 uses: https://github.com/docker/login-action@v3
with: with:
registry: gitea.homelab.fhirworx.io registry: gitea.homelab.fhirworx.io
username: ${{ secrets.REGISTRY_USER }} username: ${{ secrets.REGISTRY_USER }}
@@ -28,7 +28,7 @@ jobs:
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV" run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
- name: Build notebooks - name: Build notebooks
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: notebooks/ context: notebooks/
file: notebooks/Dockerfile file: notebooks/Dockerfile
@@ -36,7 +36,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
- name: Build zotero - name: Build zotero
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: zotero/ context: zotero/
file: zotero/Dockerfile file: zotero/Dockerfile
@@ -44,7 +44,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
- name: Build docs - name: Build docs
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: docs/Dockerfile file: docs/Dockerfile
@@ -52,7 +52,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
- name: Build api - name: Build api
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: api/Dockerfile file: api/Dockerfile
@@ -60,7 +60,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
- name: Build mc - name: Build mc
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: rustfs/ context: rustfs/
file: rustfs/Dockerfile.mc file: rustfs/Dockerfile.mc
@@ -72,13 +72,13 @@ jobs:
needs: build needs: build
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Compute short SHA - name: Compute short SHA
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV" run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
- name: Scan notebooks - name: Scan notebooks
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -87,7 +87,7 @@ jobs:
output: notebooks-scan.json output: notebooks-scan.json
- name: Scan zotero - name: Scan zotero
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -96,7 +96,7 @@ jobs:
output: zotero-scan.json output: zotero-scan.json
- name: Scan docs - name: Scan docs
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -105,7 +105,7 @@ jobs:
output: docs-scan.json output: docs-scan.json
- name: Scan api - name: Scan api
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -114,7 +114,7 @@ jobs:
output: api-scan.json output: api-scan.json
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans name: trivy-scans
path: "*-scan.json" path: "*-scan.json"
@@ -124,15 +124,15 @@ jobs:
needs: scan needs: scan
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
uses: astral-sh/setup-uv@v4 uses: https://github.com/astral-sh/setup-uv@v4
with: with:
version: latest version: latest
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans name: trivy-scans

View File

@@ -13,20 +13,20 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Log in to container registry - name: Log in to container registry
uses: docker/login-action@v3 uses: https://github.com/docker/login-action@v3
with: with:
registry: gitea.homelab.fhirworx.io registry: gitea.homelab.fhirworx.io
username: ${{ secrets.REGISTRY_USER }} username: ${{ secrets.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_TOKEN }} password: ${{ secrets.REGISTRY_TOKEN }}
- name: Build notebooks - name: Build notebooks
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: notebooks/ context: notebooks/
file: notebooks/Dockerfile file: notebooks/Dockerfile
@@ -35,7 +35,7 @@ jobs:
no-cache: true no-cache: true
- name: Build zotero - name: Build zotero
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: zotero/ context: zotero/
file: zotero/Dockerfile file: zotero/Dockerfile
@@ -44,7 +44,7 @@ jobs:
no-cache: true no-cache: true
- name: Build docs - name: Build docs
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: docs/Dockerfile file: docs/Dockerfile
@@ -53,7 +53,7 @@ jobs:
no-cache: true no-cache: true
- name: Build api - name: Build api
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: api/Dockerfile file: api/Dockerfile
@@ -62,7 +62,7 @@ jobs:
no-cache: true no-cache: true
- name: Build mc - name: Build mc
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: rustfs/ context: rustfs/
file: rustfs/Dockerfile.mc file: rustfs/Dockerfile.mc
@@ -75,10 +75,10 @@ jobs:
needs: build needs: build
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Scan notebooks - name: Scan notebooks
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:hardened image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:hardened
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -87,7 +87,7 @@ jobs:
output: notebooks-scan.json output: notebooks-scan.json
- name: Scan zotero - name: Scan zotero
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:hardened image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:hardened
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -96,7 +96,7 @@ jobs:
output: zotero-scan.json output: zotero-scan.json
- name: Scan docs - name: Scan docs
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:hardened image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:hardened
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -105,7 +105,7 @@ jobs:
output: docs-scan.json output: docs-scan.json
- name: Scan api - name: Scan api
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:hardened image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:hardened
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -114,7 +114,7 @@ jobs:
output: api-scan.json output: api-scan.json
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans-harden name: trivy-scans-harden
path: "*-scan.json" path: "*-scan.json"
@@ -124,15 +124,15 @@ jobs:
needs: scan needs: scan
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
uses: astral-sh/setup-uv@v4 uses: https://github.com/astral-sh/setup-uv@v4
with: with:
version: latest version: latest
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans-harden name: trivy-scans-harden

View File

@@ -28,18 +28,18 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Hadolint notebooks - name: Hadolint notebooks
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: notebooks/Dockerfile dockerfile: notebooks/Dockerfile
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Build notebooks - name: Build notebooks
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: notebooks/ context: notebooks/
file: notebooks/Dockerfile file: notebooks/Dockerfile
@@ -51,18 +51,18 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Hadolint zotero - name: Hadolint zotero
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: zotero/Dockerfile dockerfile: zotero/Dockerfile
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Build zotero - name: Build zotero
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: zotero/ context: zotero/
file: zotero/Dockerfile file: zotero/Dockerfile
@@ -74,18 +74,18 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Hadolint docs - name: Hadolint docs
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: docs/Dockerfile dockerfile: docs/Dockerfile
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Build docs - name: Build docs
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: docs/Dockerfile file: docs/Dockerfile
@@ -97,18 +97,18 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Hadolint api - name: Hadolint api
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: api/Dockerfile dockerfile: api/Dockerfile
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Build api - name: Build api
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: api/Dockerfile file: api/Dockerfile
@@ -120,18 +120,18 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Hadolint mc - name: Hadolint mc
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: rustfs/Dockerfile.mc dockerfile: rustfs/Dockerfile.mc
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Build mc - name: Build mc
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: rustfs/ context: rustfs/
file: rustfs/Dockerfile.mc file: rustfs/Dockerfile.mc

View File

@@ -11,13 +11,13 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: https://github.com/docker/setup-buildx-action@v3
- name: Log in to container registry - name: Log in to container registry
uses: docker/login-action@v3 uses: https://github.com/docker/login-action@v3
with: with:
registry: gitea.homelab.fhirworx.io registry: gitea.homelab.fhirworx.io
username: ${{ secrets.REGISTRY_USER }} username: ${{ secrets.REGISTRY_USER }}
@@ -27,7 +27,7 @@ jobs:
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV" run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
- name: Build notebooks - name: Build notebooks
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: notebooks/ context: notebooks/
file: notebooks/Dockerfile file: notebooks/Dockerfile
@@ -35,7 +35,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest tags: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/notebooks:latest
- name: Build zotero - name: Build zotero
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: zotero/ context: zotero/
file: zotero/Dockerfile file: zotero/Dockerfile
@@ -43,7 +43,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest tags: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/zotero:latest
- name: Build docs - name: Build docs
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: docs/Dockerfile file: docs/Dockerfile
@@ -51,7 +51,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest tags: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/docs:latest
- name: Build api - name: Build api
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: . context: .
file: api/Dockerfile file: api/Dockerfile
@@ -59,7 +59,7 @@ jobs:
tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest tags: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }},gitea.homelab.fhirworx.io/homelab/stack/api:latest
- name: Build mc - name: Build mc
uses: docker/build-push-action@v6 uses: https://github.com/docker/build-push-action@v6
with: with:
context: rustfs/ context: rustfs/
file: rustfs/Dockerfile.mc file: rustfs/Dockerfile.mc
@@ -71,13 +71,13 @@ jobs:
needs: build needs: build
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Compute short SHA - name: Compute short SHA
run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV" run: echo "SHORT_SHA=${{GITHUB_SHA::8}}" >> "$GITHUB_ENV"
- name: Scan notebooks - name: Scan notebooks
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/notebooks:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -86,7 +86,7 @@ jobs:
output: notebooks-scan.json output: notebooks-scan.json
- name: Scan zotero - name: Scan zotero
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/zotero:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -95,7 +95,7 @@ jobs:
output: zotero-scan.json output: zotero-scan.json
- name: Scan docs - name: Scan docs
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/docs:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -104,7 +104,7 @@ jobs:
output: docs-scan.json output: docs-scan.json
- name: Scan api - name: Scan api
uses: aquasecurity/trivy-action@master uses: https://github.com/aquasecurity/trivy-action@master
with: with:
image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }} image-ref: gitea.homelab.fhirworx.io/homelab/stack/api:${{ env.SHORT_SHA }}
severity: HIGH,CRITICAL severity: HIGH,CRITICAL
@@ -113,7 +113,7 @@ jobs:
output: api-scan.json output: api-scan.json
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans-rebuild name: trivy-scans-rebuild
path: "*-scan.json" path: "*-scan.json"
@@ -123,15 +123,15 @@ jobs:
needs: scan needs: scan
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
uses: astral-sh/setup-uv@v4 uses: https://github.com/astral-sh/setup-uv@v4
with: with:
version: latest version: latest
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans-rebuild name: trivy-scans-rebuild

View File

@@ -12,10 +12,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: https://github.com/actions/checkout@v4
- name: Set up uv - name: Set up uv
uses: astral-sh/setup-uv@v4 uses: https://github.com/astral-sh/setup-uv@v4
with: with:
version: latest version: latest
@@ -23,7 +23,7 @@ jobs:
run: uv build --out-dir dist/ run: uv build --out-dir dist/
- name: Create release - name: Create release
uses: softprops/action-gh-release@v2 uses: https://github.com/softprops/action-gh-release@v2
with: with:
files: | files: |
dist/*.whl dist/*.whl

View File

@@ -12,13 +12,96 @@ from __future__ import annotations
from backends.github import ( from backends.github import (
_HEADER, _HEADER,
_build_push_step,
_checkout_step,
_setup_buildx_step,
_setup_uv_step,
_trivy_step,
) )
# ── Override action refs with full GitHub URLs ───────────────────
# Gitea Actions resolves short refs (e.g. actions/checkout@v4) against
# the local Gitea instance. Use full URLs to pull from GitHub.
def _checkout_step() -> str:
return """\
- name: Checkout
uses: https://github.com/actions/checkout@v4"""
def _setup_buildx_step() -> str:
return """\
- name: Set up Docker Buildx
uses: https://github.com/docker/setup-buildx-action@v3"""
def _setup_uv_step(uv_version: str) -> str:
return f"""\
- name: Set up uv
uses: https://github.com/astral-sh/setup-uv@v4
with:
version: {uv_version}"""
def _build_push_step(
img: dict,
tags_expr: str,
registry: str,
owner_repo: str,
*,
no_cache: bool = False,
load_only: bool = False,
) -> str:
name = img["name"]
push = "false" if load_only else "true"
lines = f"""\
- name: Build {name}
uses: https://github.com/docker/build-push-action@v6
with:
context: {img["context"]}
file: {img["dockerfile"]}
push: {push}
tags: {tags_expr}"""
if load_only:
lines += "\n load: true"
if no_cache:
lines += "\n no-cache: true"
return lines
def _trivy_step(
img: dict,
tag: str,
registry: str,
owner_repo: str,
) -> str:
name = img["name"]
sev = img.get("trivy_severity", "HIGH,CRITICAL")
ec = img.get("trivy_exit_code", 0)
return f"""\
- name: Scan {name}
uses: https://github.com/aquasecurity/trivy-action@master
with:
image-ref: {registry}/{owner_repo}/{name}:{tag}
severity: {sev}
exit-code: "{ec}"
format: json
output: {name}-scan.json"""
def _upload_artifact_step(name: str, path: str) -> str:
return f"""\
- name: Upload {name}
uses: https://github.com/actions/upload-artifact@v4
with:
name: {name}
path: "{path}\""""
def _download_artifact_step(name: str) -> str:
return f"""\
- name: Download {name}
uses: https://github.com/actions/download-artifact@v4
with:
name: {name}"""
# ── Gitea-specific helpers ─────────────────────────────────────── # ── Gitea-specific helpers ───────────────────────────────────────
@@ -26,7 +109,7 @@ def _docker_login_step(registry: str) -> str:
"""Login using PAT secret — GITEA_TOKEN can't push to registry.""" """Login using PAT secret — GITEA_TOKEN can't push to registry."""
return f"""\ return f"""\
- name: Log in to container registry - name: Log in to container registry
uses: docker/login-action@v3 uses: https://github.com/docker/login-action@v3
with: with:
registry: {registry} registry: {registry}
username: ${{{{ secrets.REGISTRY_USER }}}} username: ${{{{ secrets.REGISTRY_USER }}}}
@@ -135,7 +218,7 @@ jobs:
{scan_block} {scan_block}
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans name: trivy-scans
path: "*-scan.json" path: "*-scan.json"
@@ -149,7 +232,7 @@ jobs:
{_setup_uv_step(uv_version)} {_setup_uv_step(uv_version)}
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans name: trivy-scans
@@ -222,7 +305,7 @@ jobs:
{scan_block} {scan_block}
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans-harden name: trivy-scans-harden
path: "*-scan.json" path: "*-scan.json"
@@ -236,7 +319,7 @@ jobs:
{_setup_uv_step(uv_version)} {_setup_uv_step(uv_version)}
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans-harden name: trivy-scans-harden
@@ -316,7 +399,7 @@ jobs:
{scan_block} {scan_block}
- name: Upload scan results - name: Upload scan results
uses: actions/upload-artifact@v4 uses: https://github.com/actions/upload-artifact@v4
with: with:
name: trivy-scans-rebuild name: trivy-scans-rebuild
path: "*-scan.json" path: "*-scan.json"
@@ -330,7 +413,7 @@ jobs:
{_setup_uv_step(uv_version)} {_setup_uv_step(uv_version)}
- name: Download scan results - name: Download scan results
uses: actions/download-artifact@v4 uses: https://github.com/actions/download-artifact@v4
with: with:
name: trivy-scans-rebuild name: trivy-scans-rebuild
@@ -368,7 +451,7 @@ def _gen_infra_ci(
{_checkout_step()} {_checkout_step()}
- name: Hadolint {name} - name: Hadolint {name}
uses: hadolint/hadolint-action@v3.1.0 uses: https://github.com/hadolint/hadolint-action@v3.1.0
with: with:
dockerfile: {img["dockerfile"]} dockerfile: {img["dockerfile"]}
@@ -417,7 +500,7 @@ jobs:
run: uv build --out-dir dist/ run: uv build --out-dir dist/
- name: Create release - name: Create release
uses: softprops/action-gh-release@v2 uses: https://github.com/softprops/action-gh-release@v2
with: with:
files: | files: |
dist/*.whl dist/*.whl