mirror of
https://github.com/docker/build-push-action.git
synced 2026-10-04 08:44:35 +03:00
Merge pull request #1086 from crazy-max/fix-attests-provenance-sbom
handle attests correctly with provenance and sbom inputs
This commit is contained in:
4 files changed
+128
-43
No files matched your search
+74
-14
@@ -481,7 +481,7 @@ nproc=3`],
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--provenance", `mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
@@ -500,7 +500,7 @@ nproc=3`],
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--provenance", `builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
@@ -519,7 +519,7 @@ nproc=3`],
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--provenance", `mode=max,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,mode=max,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
@@ -538,7 +538,7 @@ nproc=3`],
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--provenance", 'false',
|
||||
'--attest', 'type=provenance,disabled=true',
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
@@ -557,7 +557,7 @@ nproc=3`],
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--provenance", 'builder-id=foo',
|
||||
'--attest', 'type=provenance,builder-id=foo',
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
@@ -620,7 +620,7 @@ nproc=3`],
|
||||
]
|
||||
],
|
||||
[
|
||||
25,
|
||||
26,
|
||||
'0.10.0',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
@@ -642,7 +642,7 @@ ANOTHER_SECRET=ANOTHER_SECRET_ENV`]
|
||||
]
|
||||
],
|
||||
[
|
||||
26,
|
||||
27,
|
||||
'0.10.0',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
@@ -663,7 +663,7 @@ ANOTHER_SECRET=ANOTHER_SECRET_ENV`]
|
||||
]
|
||||
],
|
||||
[
|
||||
27,
|
||||
28,
|
||||
'0.11.0',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
@@ -677,13 +677,13 @@ ANOTHER_SECRET=ANOTHER_SECRET_ENV`]
|
||||
[
|
||||
'build',
|
||||
'--output', 'type=local,dest=./release-out',
|
||||
"--provenance", `mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
],
|
||||
[
|
||||
28,
|
||||
29,
|
||||
'0.12.0',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
@@ -701,13 +701,13 @@ ANOTHER_SECRET=ANOTHER_SECRET_ENV`]
|
||||
'--annotation', 'manifest:example3=yyy',
|
||||
'--annotation', 'manifest-descriptor[linux/amd64]:example4=zzz',
|
||||
'--output', 'type=local,dest=./release-out',
|
||||
"--provenance", `mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
],
|
||||
[
|
||||
29,
|
||||
30,
|
||||
'0.12.0',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
@@ -721,11 +721,71 @@ ANOTHER_SECRET=ANOTHER_SECRET_ENV`]
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
"--output", `type=image,"name=localhost:5000/name/app:latest,localhost:5000/name/app:foo",push-by-digest=true,name-canonical=true,push=true`,
|
||||
"--provenance", `mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=provenance,mode=min,inline-only=true,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
]
|
||||
],
|
||||
[
|
||||
31,
|
||||
'0.13.1',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
['load', 'false'],
|
||||
['no-cache', 'false'],
|
||||
['push', 'false'],
|
||||
['pull', 'false'],
|
||||
['provenance', 'mode=max'],
|
||||
['sbom', 'true'],
|
||||
]),
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
'--attest', `type=provenance,mode=max,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--attest', `type=sbom,disabled=false`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
],
|
||||
[
|
||||
32,
|
||||
'0.13.1',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
['load', 'false'],
|
||||
['no-cache', 'false'],
|
||||
['push', 'false'],
|
||||
['pull', 'false'],
|
||||
['attests', 'type=provenance,mode=min'],
|
||||
['provenance', 'mode=max'],
|
||||
]),
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
'--attest', `type=provenance,mode=max,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
],
|
||||
[
|
||||
33,
|
||||
'0.13.1',
|
||||
new Map<string, string>([
|
||||
['context', '.'],
|
||||
['load', 'false'],
|
||||
['no-cache', 'false'],
|
||||
['push', 'false'],
|
||||
['pull', 'false'],
|
||||
['attests', 'type=provenance,mode=min'],
|
||||
]),
|
||||
[
|
||||
'build',
|
||||
'--iidfile', path.join(tmpDir, 'iidfile'),
|
||||
'--attest', `type=provenance,mode=min,builder-id=https://github.com/docker/build-push-action/actions/runs/123456789`,
|
||||
'--metadata-file', path.join(tmpDir, 'metadata-file'),
|
||||
'.'
|
||||
]
|
||||
],
|
||||
])(
|
||||
'[%d] given %p with %p as inputs, returns %p',
|
||||
async (num: number, buildxVersion: string, inputs: Map<string, string>, expected: Array<string>) => {
|
||||
|
||||
+1
-1
@@ -28,5 +28,5 @@ e.exports=r(3765)},3583:(e,t,r)=>{"use strict";
|
||||
*/
|
||||
const i=r(7147);const s=r(2037);const n=r(1017);const a=r(6113);const o={fs:i.constants,os:s.constants};const l="0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz",c=/XXXXXX/,p=3,d=(o.O_CREAT||o.fs.O_CREAT)|(o.O_EXCL||o.fs.O_EXCL)|(o.O_RDWR||o.fs.O_RDWR),A=s.platform()==="win32",u=o.EBADF||o.os.errno.EBADF,m=o.ENOENT||o.os.errno.ENOENT,h=448,g=384,E="exit",y=[],C=i.rmdirSync.bind(i);let b=false;function rimraf(e,t){return i.rm(e,{recursive:true},t)}function FN_RIMRAF_SYNC(e){return i.rmSync(e,{recursive:true})}function tmpName(e,t){const r=_parseArguments(e,t),s=r[0],n=r[1];try{_assertAndSanitizeOptions(s)}catch(e){return n(e)}let a=s.tries;(function _getUniqueName(){try{const e=_generateTmpName(s);i.stat(e,(function(t){if(!t){if(a-- >0)return _getUniqueName();return n(new Error("Could not get a unique tmp filename, max tries reached "+e))}n(null,e)}))}catch(e){n(e)}})()}function tmpNameSync(e){const t=_parseArguments(e),r=t[0];_assertAndSanitizeOptions(r);let s=r.tries;do{const e=_generateTmpName(r);try{i.statSync(e)}catch(t){return e}}while(s-- >0);throw new Error("Could not get a unique tmp filename, max tries reached")}function file(e,t){const r=_parseArguments(e,t),s=r[0],n=r[1];tmpName(s,(function _tmpNameCreated(e,t){if(e)return n(e);i.open(t,d,s.mode||g,(function _fileCreated(e,r){if(e)return n(e);if(s.discardDescriptor){return i.close(r,(function _discardCallback(e){return n(e,t,undefined,_prepareTmpFileRemoveCallback(t,-1,s,false))}))}else{const e=s.discardDescriptor||s.detachDescriptor;n(null,t,r,_prepareTmpFileRemoveCallback(t,e?-1:r,s,false))}}))}))}function fileSync(e){const t=_parseArguments(e),r=t[0];const s=r.discardDescriptor||r.detachDescriptor;const n=tmpNameSync(r);var a=i.openSync(n,d,r.mode||g);if(r.discardDescriptor){i.closeSync(a);a=undefined}return{name:n,fd:a,removeCallback:_prepareTmpFileRemoveCallback(n,s?-1:a,r,true)}}function dir(e,t){const r=_parseArguments(e,t),s=r[0],n=r[1];tmpName(s,(function _tmpNameCreated(e,t){if(e)return n(e);i.mkdir(t,s.mode||h,(function _dirCreated(e){if(e)return n(e);n(null,t,_prepareTmpDirRemoveCallback(t,s,false))}))}))}function dirSync(e){const t=_parseArguments(e),r=t[0];const s=tmpNameSync(r);i.mkdirSync(s,r.mode||h);return{name:s,removeCallback:_prepareTmpDirRemoveCallback(s,r,true)}}function _removeFileAsync(e,t){const _handler=function(e){if(e&&!_isENOENT(e)){return t(e)}t()};if(0<=e[0])i.close(e[0],(function(){i.unlink(e[1],_handler)}));else i.unlink(e[1],_handler)}function _removeFileSync(e){let t=null;try{if(0<=e[0])i.closeSync(e[0])}catch(e){if(!_isEBADF(e)&&!_isENOENT(e))throw e}finally{try{i.unlinkSync(e[1])}catch(e){if(!_isENOENT(e))t=e}}if(t!==null){throw t}}function _prepareTmpFileRemoveCallback(e,t,r,i){const s=_prepareRemoveCallback(_removeFileSync,[t,e],i);const n=_prepareRemoveCallback(_removeFileAsync,[t,e],i,s);if(!r.keep)y.unshift(s);return i?s:n}function _prepareTmpDirRemoveCallback(e,t,r){const s=t.unsafeCleanup?rimraf:i.rmdir.bind(i);const n=t.unsafeCleanup?FN_RIMRAF_SYNC:C;const a=_prepareRemoveCallback(n,e,r);const o=_prepareRemoveCallback(s,e,r,a);if(!t.keep)y.unshift(a);return r?a:o}function _prepareRemoveCallback(e,t,r,i){let s=false;return function _cleanupCallback(n){if(!s){const a=i||_cleanupCallback;const o=y.indexOf(a);if(o>=0)y.splice(o,1);s=true;if(r||e===C||e===FN_RIMRAF_SYNC){return e(t)}else{return e(t,n||function(){})}}}}function _garbageCollector(){if(!b)return;while(y.length){try{y[0]()}catch(e){}}}function _randomChars(e){let t=[],r=null;try{r=a.randomBytes(e)}catch(t){r=a.pseudoRandomBytes(e)}for(var i=0;i<e;i++){t.push(l[r[i]%l.length])}return t.join("")}function _isBlank(e){return e===null||_isUndefined(e)||!e.trim()}function _isUndefined(e){return typeof e==="undefined"}function _parseArguments(e,t){if(typeof e==="function"){return[{},e]}if(_isUndefined(e)){return[{},t]}const r={};for(const t of Object.getOwnPropertyNames(e)){r[t]=e[t]}return[r,t]}function _generateTmpName(e){const t=e.tmpdir;if(!_isUndefined(e.name))return n.join(t,e.dir,e.name);if(!_isUndefined(e.template))return n.join(t,e.dir,e.template).replace(c,_randomChars(6));const r=[e.prefix?e.prefix:"tmp","-",process.pid,"-",_randomChars(12),e.postfix?"-"+e.postfix:""].join("");return n.join(t,e.dir,r)}function _assertAndSanitizeOptions(e){e.tmpdir=_getTmpDir(e);const t=e.tmpdir;if(!_isUndefined(e.name))_assertIsRelative(e.name,"name",t);if(!_isUndefined(e.dir))_assertIsRelative(e.dir,"dir",t);if(!_isUndefined(e.template)){_assertIsRelative(e.template,"template",t);if(!e.template.match(c))throw new Error(`Invalid template, found "${e.template}".`)}if(!_isUndefined(e.tries)&&isNaN(e.tries)||e.tries<0)throw new Error(`Invalid tries, found "${e.tries}".`);e.tries=_isUndefined(e.name)?e.tries||p:1;e.keep=!!e.keep;e.detachDescriptor=!!e.detachDescriptor;e.discardDescriptor=!!e.discardDescriptor;e.unsafeCleanup=!!e.unsafeCleanup;e.dir=_isUndefined(e.dir)?"":n.relative(t,_resolvePath(e.dir,t));e.template=_isUndefined(e.template)?unLine truncated
|
||||
/*! formdata-polyfill. MIT License. Jimmy Wärting <https://jimmy.warting.se/opensource> */;const escape=e=>e.replace(/\n/g,"%0A").replace(/\r/g,"%0D").replace(/"/g,"%22");const normalizeLinefeeds=e=>e.replace(/\r?\n|\r/g,"\r\n");const i=[];const s=new Uint8Array([13,10]);d=0;let n=false;for(const[t,a]of e){if(typeof a==="string"){const e=N.encode(r+`; name="${escape(normalizeLinefeeds(t))}"`+`\r\n\r\n${normalizeLinefeeds(a)}\r\n`);i.push(e);d+=e.byteLength}else{const e=N.encode(`${r}; name="${escape(normalizeLinefeeds(t))}"`+(a.name?`; filename="${escape(a.name)}"`:"")+"\r\n"+`Content-Type: ${a.type||"application/octet-stream"}\r\n\r\n`);i.push(e,a,s);if(typeof a.size==="number"){d+=e.byteLength+a.size+s.byteLength}else{n=true}}}const a=N.encode(`--${t}--`);i.push(a);d+=a.byteLength;if(n){d=null}p=e;c=async function*(){for(const e of i){if(e.stream){yield*e.stream()}else{yield e}}};A="multipart/form-data; boundary="+t}else if(a(e)){p=e;d=e.size;if(e.type){A=e.type}}else if(typeof e[Symbol.asyncIterator]==="function"){if(t){throw new TypeError("keepalive")}if(s.isDisturbed(e)||e.locked){throw new TypeError("Response body object should not be disturbed or locked")}i=e instanceof S?e:n(e)}if(typeof p==="string"||s.isBuffer(p)){d=Buffer.byteLength(p)}if(c!=null){let t;i=new S({async start(){t=c(e)[Symbol.asyncIterator]()},async pull(e){const{value:r,done:s}=await t.next();if(s){queueMicrotask((()=>{e.close()}))}else{if(!b(i)){e.enqueue(new Uint8Array(r))}}return e.desiredSize>0},async cancel(e){await t.return()},type:undefined})}const u={stream:i,source:p,length:d};return[u,A]}function safelyExtractBody(e,t=false){if(!S){S=r(5356).ReadableStream}if(e instanceof S){C(!s.isDisturbed(e),"The body has already been consumed.");C(!e.locked,"The stream is locked.")}return extractBody(e,t)}function cloneBody(e){const[t,r]=e.stream.tee();const i=h(r,{transfer:[r]});const[,s]=i.tee();e.stream=t;return{stream:s,length:e.length,source:e.source}}async function*consumeBody(e){if(e){if(I(e)){yield e}else{const t=e.stream;if(s.isDisturbed(t)){throw new TypeError("The body has already been consumed.")}if(t.locked){throw new TypeError("The stream is locked.")}t[y]=true;yield*t}}}function throwIfAborted(e){if(e.aborted){throw new m("The operation was aborted.","AbortError")}}function bodyMixinMethods(e){const t={blob(){return specConsumeBody(this,(e=>{let t=bodyMimeType(this);if(t==="failure"){t=""}else if(t){t=w(t)}return new g([e],{type:t})}),e)},arrayBuffer(){return specConsumeBody(this,(e=>new Uint8Array(e).buffer),e)},text(){return specConsumeBody(this,utf8DecodeBytes,e)},json(){return specConsumeBody(this,parseJSONFromBytes,e)},async formData(){u.brandCheck(this,e);throwIfAborted(this[A]);const t=this.headers.get("Content-Type");if(/multipart\/form-data/.test(t)){const e={};for(const[t,r]of this.headers)e[t.toLowerCase()]=r;const t=new d;let r;try{r=new i({headers:e,preservePath:true})}catch(e){throw new m(`${e}`,"AbortError")}r.on("field",((e,r)=>{t.append(e,r)}));r.on("file",((e,r,i,s,n)=>{const a=[];if(s==="base64"||s.toLowerCase()==="base64"){let s="";r.on("data",(e=>{s+=e.toString().replace(/[\r\n]/gm,"");const t=s.length-s.length%4;a.push(Buffer.from(s.slice(0,t),"base64"));s=s.slice(t)}));r.on("end",(()=>{a.push(Buffer.from(s,"base64"));t.append(e,new x(a,i,{type:n}))}))}else{r.on("data",(e=>{a.push(e)}));r.on("end",(()=>{t.append(e,new x(a,i,{type:n}))}))}}));const s=new Promise(((e,t)=>{r.on("finish",e);r.on("error",(e=>t(new TypeError(e))))}));if(this.body!==null)for await(const e of consumeBody(this[A].body))r.write(e);r.end();await s;return t}else if(/application\/x-www-form-urlencoded/.test(t)){let e;try{let t="";const r=new TextDecoder("utf-8",{ignoreBOM:true});for await(const e of consumeBody(this[A].body)){if(!I(e)){throw new TypeError("Expected Uint8Array chunk")}t+=r.decode(e,{stream:true})}t+=r.decode();e=new URLSearchParams(t)}catch(e){throw Object.assign(new TypeError,{cause:e})}const t=new d;for(const[r,i]of e){t.append(r,i)}return t}else{await Promise.resolve();throwIfAborted(this[A]);throw u.errors.exception({header:`${e.name}.formData`,message:"Could not parse content as FormData."})}}};return t}function mixinBody(e){Object.assign(e.prototype,bodyMixinMethods(e))}async function specConsumeBody(e,t,r){u.brandCheck(e,r);throwIfAborted(e[A]);if(bodyUnusable(e[A].body)){throw new TypeError("Body is unusable")}const i=c();const errorSteps=e=>i.reject(e);const successSteps=e=>{try{i.resolve(t(e))}catch(e){errorSteps(e)}};if(e[A].body==null){successSteps(new Uint8Array);return i.promise}await p(e[A].body,successSteps,errorSteps);return i.promise}function bodyUnusable(e){return e!=null&&(e.stream.locked||s.isDisturbed(e.stream))}function utf8DecodeBytes(e){if(e.length===0){return""}if(e[0]===239&&e[1]===187&&e[2]===191){e=e.subarray(3)}const t=R.decode(e);return t}function parseJSONFromBytes(e){return JSON.parse(utf8DecodeBytes(e))}function bodyMimeType(e){const{headersList:t}=e[A];const r=t.get("content-Line truncated
|
||||
/*! ws. MIT License. Einar Otto Stangvik <einaros@gmail.com> */n[s-4]=this.maskKey[0];n[s-3]=this.maskKey[1];n[s-2]=this.maskKey[2];n[s-1]=this.maskKey[3];n[1]=r;if(r===126){n.writeUInt16BE(t,2)}else if(r===127){n[2]=n[3]=0;n.writeUIntBE(t,4,6)}n[1]|=128;for(let e=0;e<t;e++){n[s+e]=this.frameData[e]^this.maskKey[e%4]}return n}}e.exports={WebsocketFrameSend:WebsocketFrameSend}},1688:(e,t,r)=>{"use strict";const{Writable:i}=r(2781);const s=r(7643);const{parserStates:n,opcodes:a,states:o,emptyBuffer:l}=r(9188);const{kReadyState:c,kSentClose:p,kResponse:d,kReceivedClose:A}=r(7578);const{isValidStatusCode:u,failWebsocketConnection:m,websocketMessageReceived:h}=r(5515);const{WebsocketFrameSend:g}=r(5444);const E={};E.ping=s.channel("undici:websocket:ping");E.pong=s.channel("undici:websocket:pong");class ByteParser extends i{#a=[];#o=0;#l=n.INFO;#c={};#p=[];constructor(e){super();this.ws=e}_write(e,t,r){this.#a.push(e);this.#o+=e.length;this.run(r)}run(e){while(true){if(this.#l===n.INFO){if(this.#o<2){return e()}const t=this.consume(2);this.#c.fin=(t[0]&128)!==0;this.#c.opcode=t[0]&15;this.#c.originalOpcode??=this.#c.opcode;this.#c.fragmented=!this.#c.fin&&this.#c.opcode!==a.CONTINUATION;if(this.#c.fragmented&&this.#c.opcode!==a.BINARY&&this.#c.opcode!==a.TEXT){m(this.ws,"Invalid frame type was fragmented.");return}const r=t[1]&127;if(r<=125){this.#c.payloadLength=r;this.#l=n.READ_DATA}else if(r===126){this.#l=n.PAYLOADLENGTH_16}else if(r===127){this.#l=n.PAYLOADLENGTH_64}if(this.#c.fragmented&&r>125){m(this.ws,"Fragmented frame exceeded 125 bytes.");return}else if((this.#c.opcode===a.PING||this.#c.opcode===a.PONG||this.#c.opcode===a.CLOSE)&&r>125){m(this.ws,"Payload length for control frame exceeded 125 bytes.");return}else if(this.#c.opcode===a.CLOSE){if(r===1){m(this.ws,"Received close frame with a 1-byte body.");return}const e=this.consume(r);this.#c.closeInfo=this.parseCloseBody(false,e);if(!this.ws[p]){const e=Buffer.allocUnsafe(2);e.writeUInt16BE(this.#c.closeInfo.code,0);const t=new g(e);this.ws[d].socket.write(t.createFrame(a.CLOSE),(e=>{if(!e){this.ws[p]=true}}))}this.ws[c]=o.CLOSING;this.ws[A]=true;this.end();return}else if(this.#c.opcode===a.PING){const t=this.consume(r);if(!this.ws[A]){const e=new g(t);this.ws[d].socket.write(e.createFrame(a.PONG));if(E.ping.hasSubscribers){E.ping.publish({payload:t})}}this.#l=n.INFO;if(this.#o>0){continue}else{e();return}}else if(this.#c.opcode===a.PONG){const t=this.consume(r);if(E.pong.hasSubscribers){E.pong.publish({payload:t})}if(this.#o>0){continue}else{e();return}}}else if(this.#l===n.PAYLOADLENGTH_16){if(this.#o<2){return e()}const t=this.consume(2);this.#c.payloadLength=t.readUInt16BE(0);this.#l=n.READ_DATA}else if(this.#l===n.PAYLOADLENGTH_64){if(this.#o<8){return e()}const t=this.consume(8);const r=t.readUInt32BE(0);if(r>2**31-1){m(this.ws,"Received payload length > 2^31 bytes.");return}const i=t.readUInt32BE(4);this.#c.payloadLength=(r<<8)+i;this.#l=n.READ_DATA}else if(this.#l===n.READ_DATA){if(this.#o<this.#c.payloadLength){return e()}else if(this.#o>=this.#c.payloadLength){const e=this.consume(this.#c.payloadLength);this.#p.push(e);if(!this.#c.fragmented||this.#c.fin&&this.#c.opcode===a.CONTINUATION){const e=Buffer.concat(this.#p);h(this.ws,this.#c.originalOpcode,e);this.#c={};this.#p.length=0}this.#l=n.INFO}}if(this.#o>0){continue}else{e();break}}}consume(e){if(e>this.#o){return null}else if(e===0){return l}if(this.#a[0].length===e){this.#o-=this.#a[0].length;return this.#a.shift()}const t=Buffer.allocUnsafe(e);let r=0;while(r!==e){const i=this.#a[0];const{length:s}=i;if(s+r===e){t.set(this.#a.shift(),r);break}else if(s+r>e){t.set(i.subarray(0,e-r),r);this.#a[0]=i.subarray(e-r);break}else{t.set(this.#a.shift(),r);r+=i.length}}this.#o-=e;return t}parseCloseBody(e,t){let r;if(t.length>=2){r=t.readUInt16BE(0)}if(e){if(!u(r)){return null}return{code:r}}let i=t.subarray(2);if(i[0]===239&&i[1]===187&&i[2]===191){i=i.subarray(3)}if(r!==undefined&&!u(r)){return null}try{i=new TextDecoder("utf-8",{fatal:true}).decode(i)}catch{return null}return{code:r,reason:i}}get closingInfo(){return this.#c.closeInfo}}e.exports={ByteParser:ByteParser}},7578:e=>{"use strict";e.exports={kWebSocketURL:Symbol("url"),kReadyState:Symbol("ready state"),kController:Symbol("controller"),kResponse:Symbol("response"),kBinaryType:Symbol("binary type"),kSentClose:Symbol("sent close"),kReceivedClose:Symbol("received close"),kByteParser:Symbol("byte parser")}},5515:(e,t,r)=>{"use strict";const{kReadyState:i,kController:s,kResponse:n,kBinaryType:a,kWebSocketURL:o}=r(7578);const{states:l,opcodes:c}=r(9188);const{MessageEvent:p,ErrorEvent:d}=r(2611);function isEstablished(e){return e[i]===l.OPEN}function isClosing(e){return e[i]===l.CLOSING}function isClosed(e){return e[i]===l.CLOSED}function fireEvent(e,t,r=Event,i){const s=new r(e,i);t.dispatchEvent(s)}function websocketMessageReceived(e,t,r){if(e[i]!==l.OPEN){return}let s;if(t===c.TEXT){try{s=new TextDecoder("utf-8",{fatal:true}).decode(r)Line truncated
|
||||
/*! ws. MIT License. Einar Otto Stangvik <einaros@gmail.com> */n[s-4]=this.maskKey[0];n[s-3]=this.maskKey[1];n[s-2]=this.maskKey[2];n[s-1]=this.maskKey[3];n[1]=r;if(r===126){n.writeUInt16BE(t,2)}else if(r===127){n[2]=n[3]=0;n.writeUIntBE(t,4,6)}n[1]|=128;for(let e=0;e<t;e++){n[s+e]=this.frameData[e]^this.maskKey[e%4]}return n}}e.exports={WebsocketFrameSend:WebsocketFrameSend}},1688:(e,t,r)=>{"use strict";const{Writable:i}=r(2781);const s=r(7643);const{parserStates:n,opcodes:a,states:o,emptyBuffer:l}=r(9188);const{kReadyState:c,kSentClose:p,kResponse:d,kReceivedClose:A}=r(7578);const{isValidStatusCode:u,failWebsocketConnection:m,websocketMessageReceived:h}=r(5515);const{WebsocketFrameSend:g}=r(5444);const E={};E.ping=s.channel("undici:websocket:ping");E.pong=s.channel("undici:websocket:pong");class ByteParser extends i{#a=[];#o=0;#l=n.INFO;#c={};#p=[];constructor(e){super();this.ws=e}_write(e,t,r){this.#a.push(e);this.#o+=e.length;this.run(r)}run(e){while(true){if(this.#l===n.INFO){if(this.#o<2){return e()}const t=this.consume(2);this.#c.fin=(t[0]&128)!==0;this.#c.opcode=t[0]&15;this.#c.originalOpcode??=this.#c.opcode;this.#c.fragmented=!this.#c.fin&&this.#c.opcode!==a.CONTINUATION;if(this.#c.fragmented&&this.#c.opcode!==a.BINARY&&this.#c.opcode!==a.TEXT){m(this.ws,"Invalid frame type was fragmented.");return}const r=t[1]&127;if(r<=125){this.#c.payloadLength=r;this.#l=n.READ_DATA}else if(r===126){this.#l=n.PAYLOADLENGTH_16}else if(r===127){this.#l=n.PAYLOADLENGTH_64}if(this.#c.fragmented&&r>125){m(this.ws,"Fragmented frame exceeded 125 bytes.");return}else if((this.#c.opcode===a.PING||this.#c.opcode===a.PONG||this.#c.opcode===a.CLOSE)&&r>125){m(this.ws,"Payload length for control frame exceeded 125 bytes.");return}else if(this.#c.opcode===a.CLOSE){if(r===1){m(this.ws,"Received close frame with a 1-byte body.");return}const e=this.consume(r);this.#c.closeInfo=this.parseCloseBody(false,e);if(!this.ws[p]){const e=Buffer.allocUnsafe(2);e.writeUInt16BE(this.#c.closeInfo.code,0);const t=new g(e);this.ws[d].socket.write(t.createFrame(a.CLOSE),(e=>{if(!e){this.ws[p]=true}}))}this.ws[c]=o.CLOSING;this.ws[A]=true;this.end();return}else if(this.#c.opcode===a.PING){const t=this.consume(r);if(!this.ws[A]){const e=new g(t);this.ws[d].socket.write(e.createFrame(a.PONG));if(E.ping.hasSubscribers){E.ping.publish({payload:t})}}this.#l=n.INFO;if(this.#o>0){continue}else{e();return}}else if(this.#c.opcode===a.PONG){const t=this.consume(r);if(E.pong.hasSubscribers){E.pong.publish({payload:t})}if(this.#o>0){continue}else{e();return}}}else if(this.#l===n.PAYLOADLENGTH_16){if(this.#o<2){return e()}const t=this.consume(2);this.#c.payloadLength=t.readUInt16BE(0);this.#l=n.READ_DATA}else if(this.#l===n.PAYLOADLENGTH_64){if(this.#o<8){return e()}const t=this.consume(8);const r=t.readUInt32BE(0);if(r>2**31-1){m(this.ws,"Received payload length > 2^31 bytes.");return}const i=t.readUInt32BE(4);this.#c.payloadLength=(r<<8)+i;this.#l=n.READ_DATA}else if(this.#l===n.READ_DATA){if(this.#o<this.#c.payloadLength){return e()}else if(this.#o>=this.#c.payloadLength){const e=this.consume(this.#c.payloadLength);this.#p.push(e);if(!this.#c.fragmented||this.#c.fin&&this.#c.opcode===a.CONTINUATION){const e=Buffer.concat(this.#p);h(this.ws,this.#c.originalOpcode,e);this.#c={};this.#p.length=0}this.#l=n.INFO}}if(this.#o>0){continue}else{e();break}}}consume(e){if(e>this.#o){return null}else if(e===0){return l}if(this.#a[0].length===e){this.#o-=this.#a[0].length;return this.#a.shift()}const t=Buffer.allocUnsafe(e);let r=0;while(r!==e){const i=this.#a[0];const{length:s}=i;if(s+r===e){t.set(this.#a.shift(),r);break}else if(s+r>e){t.set(i.subarray(0,e-r),r);this.#a[0]=i.subarray(e-r);break}else{t.set(this.#a.shift(),r);r+=i.length}}this.#o-=e;return t}parseCloseBody(e,t){let r;if(t.length>=2){r=t.readUInt16BE(0)}if(e){if(!u(r)){return null}return{code:r}}let i=t.subarray(2);if(i[0]===239&&i[1]===187&&i[2]===191){i=i.subarray(3)}if(r!==undefined&&!u(r)){return null}try{i=new TextDecoder("utf-8",{fatal:true}).decode(i)}catch{return null}return{code:r,reason:i}}get closingInfo(){return this.#c.closeInfo}}e.exports={ByteParser:ByteParser}},7578:e=>{"use strict";e.exports={kWebSocketURL:Symbol("url"),kReadyState:Symbol("ready state"),kController:Symbol("controller"),kResponse:Symbol("response"),kBinaryType:Symbol("binary type"),kSentClose:Symbol("sent close"),kReceivedClose:Symbol("received close"),kByteParser:Symbol("byte parser")}},5515:(e,t,r)=>{"use strict";const{kReadyState:i,kController:s,kResponse:n,kBinaryType:a,kWebSocketURL:o}=r(7578);const{states:l,opcodes:c}=r(9188);const{MessageEvent:p,ErrorEvent:d}=r(2611);function isEstablished(e){return e[i]===l.OPEN}function isClosing(e){return e[i]===l.CLOSING}function isClosed(e){return e[i]===l.CLOSED}function fireEvent(e,t,r=Event,i){const s=new r(e,i);t.dispatchEvent(s)}function websocketMessageReceived(e,t,r){if(e[i]!==l.OPEN){return}let s;if(t===c.TEXT){try{s=new TextDecoder("utf-8",{fatal:true}).decode(r)Line truncated
|
||||
//# sourceMappingURL=index.js.map
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"file":"index.js","names":["__createBinding","this","Object","create","o","m","k","k2","undefined","desc","getOwnPropertyDescriptor","__esModule","writable","configurable","enumerable","get","defineProperty","__setModuleDefault","v","value","__importStar","mod","result","prototype","hasOwnProperty","call","__awaiter","thisArg","_arguments","P","generator","adopt","resolve","Promise","reject","fulfilled","step","next","e","rejected","done","then","apply","exports","saveCache","restoreCache","isFeatureAvailable","ReserveCacheError","ValidationError","core","__webpack_require__","path","utils","cacheHttpClient","tar_1","Error","constructor","message","super","name","setPrototypeOf","checkPaths","paths","length","checkKey","key","regex","test","process","env","primaryKey","restoreKeys","options","enableCrossOsArchive","keys","debug","JSON","stringify","compressionMethod","getCompressionMethod","archivePath","cacheEntry","getCacheEntry","archiveLocation","lookupOnly","info","cacheKey","join","createTempDirectory","getCacheFileName","downloadCache","isDebug","listTar","archiveFileSize","getArchiveFileSizeInBytes","Math","round","extractTar","error","typedError","warning","unlinkFile","_a","_b","_c","_d","_e","cacheId","cachePaths","resolvePaths","archiveFolder","createTar","fileSizeLimit","isGhes","reserveCacheResponse","reserveCache","cacheSize","statusCode","getCacheVersion","http_client_1","auth_1","crypto","fs","url_1","downloadUtils_1","options_1","requestUtils_1","versionSalt","getCacheApiUrl","resource","baseUrl","url","createAcceptHeader","type","apiVersion","getRequestOptions","requestOptions","headers","Accept","createHttpClient","token","bearerCredentialHandler","BearerCredentialHandler","HttpClient","components","slice","push","platform","createHash","update","digest","httpClient","version","encodeURIComponent","response","retryTypedResponse","getJson","printCachesListForDiagnostics","isSuccessStatusCode","cacheResult","cacheDownloadUrl","setSecret","cacheListResult","totalCount","artifactCaches","cacheVersion","scope","creationTime","archiveUrl","URL","downloadOptions","getDownloadOptions","hostname","endsWith","useAzureSdk","downloadCacheStorageSDK","concurrentBlobDownloads","downloadCacheHttpClientConcurrent","downloadCacheHttpClient","reserveCacheRequest","postJson","getContentRange","start","end","uploadChunk","resourceUrl","openStream","additionalHeaders","uploadChunkResponse","retryHttpClientResponse","sendStream","uploadFile","fileSize","toString","fd","openSync","uploadOptions","getUploadOptions","concurrency","assertDefined","uploadConcurrency","maxChunkSize","uploadChunkSize","parallelUploads","Array","offset","all","map","chunkSize","min","createReadStream","autoClose","on","closeSync","commitCache","filesize","commitCacheRequest","size","commitCacheResponse","__asyncValues","Symbol","asyncIterator","TypeError","i","__values","iterator","verb","n","settle","d","getGnuTarPathOnWindows","exec","glob","io","semver","util","uuid_1","constants_1","IS_WINDOWS","tempDirectory","baseLocation","dest","v4","mkdirP","filePath","statSync","patterns","e_1","workspace","cwd","globber","implicitDescendants","_f","globGenerator","_g","file","relativeFile","relative","replace","RegExp","sep","e_1_1","return","promisify","unlink","getVersion","app","additionalArgs","versionOutput","ignoreReturnCode","silent","listeners","stdout","data","stderr","err","trim","clean","CompressionMethod","Gzip","ZstdWithoutLong","CacheFilename","Zstd","existsSync","GnuTarPathOnWindows","toLowerCase","includes","which","ghUrl","trimEnd","toUpperCase","isGitHubHost","isGheHost","ManifestFilename","TarFilename","SystemTarPathOnWindows","SocketTimeout","DefaultRetryDelay","DefaultRetryAttempts","ArchiveToolType","DownloadProgress","storage_blob_1","buffer","stream","abort_controller_1","pipeResponseToStream","output","pipeline","contentLength","segmentIndex","segmentSize","segmentOffset","receivedBytes","displayedComplete","startTime","Date","now","nextSegment","setReceivedBytes","getTransferredBytes","isDone","display","transferredBytes","percentage","toFixed","elapsedTime","downloadSpeed","onProgress","progress","loadedBytes","startDisplayTimer","delayInMs","displayCallback","timeoutHandle","setTimeout","stopDisplayTimer","clearTimeout","writeStream","createWriteStream","downloadResponse","socket","destroy","contentLengthHeader","expectedLength","parseInt","actualLength","archiveDescriptor","promises","open","socketTimeout","timeoutInMs","keepAlive","res","request","lengthHeader","Number","isNaN","downloads","blockSize","count","promiseGetter","downloadSegmentRetry","reverse","actives","bytesDownloaded","progressFn","activeDownloads","nextDownload","waitAndWrite","segment","race","values","write","pop","downloadConcurrency","dispose","close","retries","failures","timeout","promiseWithTimeout","downloadSegment","partRes","Range","readBodyBuffer","client","BlockBlobClient","retryOptions","tryTimeoutInMs","properties"Line truncated
|
||||
{"version":3,"file":"index.js","names":["__createBinding","this","Object","create","o","m","k","k2","undefined","desc","getOwnPropertyDescriptor","__esModule","writable","configurable","enumerable","get","defineProperty","__setModuleDefault","v","value","__importStar","mod","result","prototype","hasOwnProperty","call","__awaiter","thisArg","_arguments","P","generator","adopt","resolve","Promise","reject","fulfilled","step","next","e","rejected","done","then","apply","exports","saveCache","restoreCache","isFeatureAvailable","ReserveCacheError","ValidationError","core","__webpack_require__","path","utils","cacheHttpClient","tar_1","Error","constructor","message","super","name","setPrototypeOf","checkPaths","paths","length","checkKey","key","regex","test","process","env","primaryKey","restoreKeys","options","enableCrossOsArchive","keys","debug","JSON","stringify","compressionMethod","getCompressionMethod","archivePath","cacheEntry","getCacheEntry","archiveLocation","lookupOnly","info","cacheKey","join","createTempDirectory","getCacheFileName","downloadCache","isDebug","listTar","archiveFileSize","getArchiveFileSizeInBytes","Math","round","extractTar","error","typedError","warning","unlinkFile","_a","_b","_c","_d","_e","cacheId","cachePaths","resolvePaths","archiveFolder","createTar","fileSizeLimit","isGhes","reserveCacheResponse","reserveCache","cacheSize","statusCode","getCacheVersion","http_client_1","auth_1","crypto","fs","url_1","downloadUtils_1","options_1","requestUtils_1","versionSalt","getCacheApiUrl","resource","baseUrl","url","createAcceptHeader","type","apiVersion","getRequestOptions","requestOptions","headers","Accept","createHttpClient","token","bearerCredentialHandler","BearerCredentialHandler","HttpClient","components","slice","push","platform","createHash","update","digest","httpClient","version","encodeURIComponent","response","retryTypedResponse","getJson","printCachesListForDiagnostics","isSuccessStatusCode","cacheResult","cacheDownloadUrl","setSecret","cacheListResult","totalCount","artifactCaches","cacheVersion","scope","creationTime","archiveUrl","URL","downloadOptions","getDownloadOptions","hostname","endsWith","useAzureSdk","downloadCacheStorageSDK","concurrentBlobDownloads","downloadCacheHttpClientConcurrent","downloadCacheHttpClient","reserveCacheRequest","postJson","getContentRange","start","end","uploadChunk","resourceUrl","openStream","additionalHeaders","uploadChunkResponse","retryHttpClientResponse","sendStream","uploadFile","fileSize","toString","fd","openSync","uploadOptions","getUploadOptions","concurrency","assertDefined","uploadConcurrency","maxChunkSize","uploadChunkSize","parallelUploads","Array","offset","all","map","chunkSize","min","createReadStream","autoClose","on","closeSync","commitCache","filesize","commitCacheRequest","size","commitCacheResponse","__asyncValues","Symbol","asyncIterator","TypeError","i","__values","iterator","verb","n","settle","d","getGnuTarPathOnWindows","exec","glob","io","semver","util","uuid_1","constants_1","IS_WINDOWS","tempDirectory","baseLocation","dest","v4","mkdirP","filePath","statSync","patterns","e_1","workspace","cwd","globber","implicitDescendants","_f","globGenerator","_g","file","relativeFile","relative","replace","RegExp","sep","e_1_1","return","promisify","unlink","getVersion","app","additionalArgs","versionOutput","ignoreReturnCode","silent","listeners","stdout","data","stderr","err","trim","clean","CompressionMethod","Gzip","ZstdWithoutLong","CacheFilename","Zstd","existsSync","GnuTarPathOnWindows","toLowerCase","includes","which","ghUrl","trimEnd","toUpperCase","isGitHubHost","isGheHost","ManifestFilename","TarFilename","SystemTarPathOnWindows","SocketTimeout","DefaultRetryDelay","DefaultRetryAttempts","ArchiveToolType","DownloadProgress","storage_blob_1","buffer","stream","abort_controller_1","pipeResponseToStream","output","pipeline","contentLength","segmentIndex","segmentSize","segmentOffset","receivedBytes","displayedComplete","startTime","Date","now","nextSegment","setReceivedBytes","getTransferredBytes","isDone","display","transferredBytes","percentage","toFixed","elapsedTime","downloadSpeed","onProgress","progress","loadedBytes","startDisplayTimer","delayInMs","displayCallback","timeoutHandle","setTimeout","stopDisplayTimer","clearTimeout","writeStream","createWriteStream","downloadResponse","socket","destroy","contentLengthHeader","expectedLength","parseInt","actualLength","archiveDescriptor","promises","open","socketTimeout","timeoutInMs","keepAlive","res","request","lengthHeader","Number","isNaN","downloads","blockSize","count","promiseGetter","downloadSegmentRetry","reverse","actives","bytesDownloaded","progressFn","activeDownloads","nextDownload","waitAndWrite","segment","race","values","write","pop","downloadConcurrency","dispose","close","retries","failures","timeout","promiseWithTimeout","downloadSegment","partRes","Range","readBodyBuffer","client","BlockBlobClient","retryOptions","tryTimeoutInMs","properties"Line truncated
|
||||
+52
-27
@@ -98,13 +98,6 @@ async function getBuildArgs(inputs: Inputs, context: string, toolkit: Toolkit):
|
||||
if (inputs.allow.length > 0) {
|
||||
args.push('--allow', inputs.allow.join(','));
|
||||
}
|
||||
if (await toolkit.buildx.versionSatisfies('>=0.10.0')) {
|
||||
await Util.asyncForEach(inputs.attests, async attest => {
|
||||
args.push('--attest', attest);
|
||||
});
|
||||
} else if (inputs.attests.length > 0) {
|
||||
core.warning("Attestations are only supported by buildx >= 0.10.0; the input 'attests' is ignored.");
|
||||
}
|
||||
if (await toolkit.buildx.versionSatisfies('>=0.12.0')) {
|
||||
await Util.asyncForEach(inputs.annotations, async annotation => {
|
||||
args.push('--annotation', annotation);
|
||||
@@ -157,26 +150,9 @@ async function getBuildArgs(inputs: Inputs, context: string, toolkit: Toolkit):
|
||||
args.push('--platform', inputs.platforms.join(','));
|
||||
}
|
||||
if (await toolkit.buildx.versionSatisfies('>=0.10.0')) {
|
||||
if (inputs.provenance) {
|
||||
args.push('--provenance', inputs.provenance);
|
||||
} else if ((await toolkit.buildkit.versionSatisfies(inputs.builder, '>=0.11.0')) && !BuildxInputs.hasDockerExporter(inputs.outputs, inputs.load)) {
|
||||
// if provenance not specified and BuildKit version compatible for
|
||||
// attestation, set default provenance. Also needs to make sure user
|
||||
// doesn't want to explicitly load the image to docker.
|
||||
if (GitHub.context.payload.repository?.private ?? false) {
|
||||
// if this is a private repository, we set the default provenance
|
||||
// attributes being set in buildx: https://github.com/docker/buildx/blob/fb27e3f919dcbf614d7126b10c2bc2d0b1927eb6/build/build.go#L603
|
||||
args.push('--provenance', BuildxInputs.resolveProvenanceAttrs(`mode=min,inline-only=true`));
|
||||
} else {
|
||||
// for a public repository, we set max provenance mode.
|
||||
args.push('--provenance', BuildxInputs.resolveProvenanceAttrs(`mode=max`));
|
||||
}
|
||||
}
|
||||
if (inputs.sbom) {
|
||||
args.push('--sbom', inputs.sbom);
|
||||
}
|
||||
} else if (inputs.provenance || inputs.sbom) {
|
||||
core.warning("Attestations are only supported by buildx >= 0.10.0; the inputs 'provenance' and 'sbom' are ignored.");
|
||||
args.push(...(await getAttestArgs(inputs, toolkit)));
|
||||
} else {
|
||||
core.warning("Attestations are only supported by buildx >= 0.10.0; the inputs 'attests', 'provenance' and 'sbom' are ignored.");
|
||||
}
|
||||
await Util.asyncForEach(inputs.secrets, async secret => {
|
||||
try {
|
||||
@@ -238,3 +214,52 @@ async function getCommonArgs(inputs: Inputs, toolkit: Toolkit): Promise<Array<st
|
||||
}
|
||||
return args;
|
||||
}
|
||||
|
||||
async function getAttestArgs(inputs: Inputs, toolkit: Toolkit): Promise<Array<string>> {
|
||||
const args: Array<string> = [];
|
||||
|
||||
// check if provenance attestation is set in attests input
|
||||
let hasAttestProvenance = false;
|
||||
await Util.asyncForEach(inputs.attests, async (attest: string) => {
|
||||
if (BuildxInputs.hasAttestationType('provenance', attest)) {
|
||||
hasAttestProvenance = true;
|
||||
}
|
||||
});
|
||||
|
||||
let provenanceSet = false;
|
||||
let sbomSet = false;
|
||||
if (inputs.provenance) {
|
||||
args.push('--attest', BuildxInputs.resolveAttestationAttrs(`type=provenance,${inputs.provenance}`));
|
||||
provenanceSet = true;
|
||||
} else if (!hasAttestProvenance && (await toolkit.buildkit.versionSatisfies(inputs.builder, '>=0.11.0')) && !BuildxInputs.hasDockerExporter(inputs.outputs, inputs.load)) {
|
||||
// if provenance not specified in provenance or attests inputs and BuildKit
|
||||
// version compatible for attestation, set default provenance. Also needs
|
||||
// to make sure user doesn't want to explicitly load the image to docker.
|
||||
if (GitHub.context.payload.repository?.private ?? false) {
|
||||
// if this is a private repository, we set the default provenance
|
||||
// attributes being set in buildx: https://github.com/docker/buildx/blob/fb27e3f919dcbf614d7126b10c2bc2d0b1927eb6/build/build.go#L603
|
||||
args.push('--attest', `type=provenance,${BuildxInputs.resolveProvenanceAttrs(`mode=min,inline-only=true`)}`);
|
||||
} else {
|
||||
// for a public repository, we set max provenance mode.
|
||||
args.push('--attest', `type=provenance,${BuildxInputs.resolveProvenanceAttrs(`mode=max`)}`);
|
||||
}
|
||||
}
|
||||
if (inputs.sbom) {
|
||||
args.push('--attest', BuildxInputs.resolveAttestationAttrs(`type=sbom,${inputs.sbom}`));
|
||||
sbomSet = true;
|
||||
}
|
||||
|
||||
// set attests but check if provenance or sbom types already set as
|
||||
// provenance and sbom inputs take precedence over attests input.
|
||||
await Util.asyncForEach(inputs.attests, async (attest: string) => {
|
||||
if (!BuildxInputs.hasAttestationType('provenance', attest) && !BuildxInputs.hasAttestationType('sbom', attest)) {
|
||||
args.push('--attest', BuildxInputs.resolveAttestationAttrs(attest));
|
||||
} else if (!provenanceSet && BuildxInputs.hasAttestationType('provenance', attest)) {
|
||||
args.push('--attest', BuildxInputs.resolveProvenanceAttrs(attest));
|
||||
} else if (!sbomSet && BuildxInputs.hasAttestationType('sbom', attest)) {
|
||||
args.push('--attest', attest);
|
||||
}
|
||||
});
|
||||
|
||||
return args;
|
||||
}
|
||||
Reference in new issue
Block a user