From 7258ffb74d36f5f5e711df8d4d0fe76a9295613f Mon Sep 17 00:00:00 2001 From: kaniini Date: Sun, 1 Oct 2023 01:28:49 +0000 Subject: [PATCH] Update images digests --- .github/workflows/build-world.yaml | 2 +- .github/workflows/build.yaml | 4 ++-- .github/workflows/ci-build.yaml | 4 ++-- .github/workflows/wolfictl-check-update.yaml | 2 +- .github/workflows/wolfictl-lint.yaml | 4 ++-- .github/workflows/wolfictl-update-gh.yaml | 2 +- .github/workflows/wolfictl-update-rm.yaml | 2 +- Makefile | 4 ++-- 8 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/build-world.yaml b/.github/workflows/build-world.yaml index ca8fc83ecb9..eee7e23e539 100644 --- a/.github/workflows/build-world.yaml +++ b/.github/workflows/build-world.yaml @@ -24,7 +24,7 @@ jobs: # permissions: container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 # TODO: Deprivilege options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index ede56d8ece8..bd210809fdf 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -30,7 +30,7 @@ jobs: # permissions: container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 # TODO: Deprivilege options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined @@ -103,7 +103,7 @@ jobs: container: # NOTE: This step only signs and uploads, so it doesn't need any privileges - image: ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 steps: - uses: actions/checkout@v3 diff --git a/.github/workflows/ci-build.yaml b/.github/workflows/ci-build.yaml index c7397bf11b0..0358248f212 100644 --- a/.github/workflows/ci-build.yaml +++ b/.github/workflows/ci-build.yaml @@ -27,7 +27,7 @@ jobs: run: | # Copy wolfictl out of the wolfictl image and onto PATH TMP=$(mktemp -d) - docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 -c "cp /usr/bin/wolfictl /out" + docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 -c "cp /usr/bin/wolfictl /out" echo "$TMP" >> $GITHUB_PATH # Assuming that we have a list of changed files such as `foo.yaml` and `bar.yaml`, this @@ -58,7 +58,7 @@ jobs: group: wolfi-builder-spot-${{ matrix.arch }} needs: changes container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --security-opt seccomp=unconfined --security-opt apparmor:unconfined diff --git a/.github/workflows/wolfictl-check-update.yaml b/.github/workflows/wolfictl-check-update.yaml index e6f73223dc5..2bccd6b5b2b 100644 --- a/.github/workflows/wolfictl-check-update.yaml +++ b/.github/workflows/wolfictl-check-update.yaml @@ -29,7 +29,7 @@ jobs: - name: Check id: check if: ${{ steps.files.outputs.all_changed_files != '' }} - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:f87f240a5386b3655b1cc27a3be3d5098b3336cf4aea359725b59d78ba007690 + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7f57828010d3e32e7457057bc76be3d19d6cb7db73b43ca8136ec2c0a4f70e7c env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: diff --git a/.github/workflows/wolfictl-lint.yaml b/.github/workflows/wolfictl-lint.yaml index 4c6cafe39cc..21eacca414c 100644 --- a/.github/workflows/wolfictl-lint.yaml +++ b/.github/workflows/wolfictl-lint.yaml @@ -19,13 +19,13 @@ jobs: - uses: actions/checkout@v3 - name: Lint id: lint - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:f87f240a5386b3655b1cc27a3be3d5098b3336cf4aea359725b59d78ba007690 + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7f57828010d3e32e7457057bc76be3d19d6cb7db73b43ca8136ec2c0a4f70e7c with: entrypoint: wolfictl args: lint --skip-rule no-makefile-entry-for-package - name: Enforce YAML formatting id: lint-yaml - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:f87f240a5386b3655b1cc27a3be3d5098b3336cf4aea359725b59d78ba007690 + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7f57828010d3e32e7457057bc76be3d19d6cb7db73b43ca8136ec2c0a4f70e7c with: entrypoint: wolfictl args: lint yam diff --git a/.github/workflows/wolfictl-update-gh.yaml b/.github/workflows/wolfictl-update-gh.yaml index 2a7c8f348d3..1901e4be317 100644 --- a/.github/workflows/wolfictl-update-gh.yaml +++ b/.github/workflows/wolfictl-update-gh.yaml @@ -23,7 +23,7 @@ jobs: steps: - uses: actions/checkout@v3 - - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:f87f240a5386b3655b1cc27a3be3d5098b3336cf4aea359725b59d78ba007690 + - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7f57828010d3e32e7457057bc76be3d19d6cb7db73b43ca8136ec2c0a4f70e7c with: entrypoint: wolfictl args: update https://github.com/${{github.repository}} --release-monitoring-query=false --github-labels request-version-update --github-labels "automated pr" diff --git a/.github/workflows/wolfictl-update-rm.yaml b/.github/workflows/wolfictl-update-rm.yaml index 6b65396c87b..43ea2fd8d26 100644 --- a/.github/workflows/wolfictl-update-rm.yaml +++ b/.github/workflows/wolfictl-update-rm.yaml @@ -23,7 +23,7 @@ jobs: steps: - uses: actions/checkout@v3 - - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:f87f240a5386b3655b1cc27a3be3d5098b3336cf4aea359725b59d78ba007690 + - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7f57828010d3e32e7457057bc76be3d19d6cb7db73b43ca8136ec2c0a4f70e7c with: entrypoint: wolfictl args: update https://github.com/${{github.repository}} --github-release-query=false --github-labels request-version-update --github-labels "automated pr" diff --git a/Makefile b/Makefile index 574bca113c8..1eaea1429c0 100644 --- a/Makefile +++ b/Makefile @@ -87,7 +87,7 @@ dev-container: -v "${PWD}:${PWD}" \ -w "${PWD}" \ -e SOURCE_DATE_EPOCH=0 \ - ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 PACKAGES_CONTAINER_FOLDER ?= /work/packages TMP_REPOSITORIES_DIR := $(shell mktemp -d) @@ -152,6 +152,6 @@ dev-container-wolfi: --mount type=bind,source="${PWD}/local-melange.rsa.pub",destination="/etc/apk/keys/local-melange.rsa.pub",readonly \ --mount type=bind,source="$(TMP_REPOSITORIES_FILE)",destination="/etc/apk/repositories",readonly \ -w "$(PACKAGES_CONTAINER_FOLDER)" \ - ghcr.io/wolfi-dev/sdk:latest@sha256:bdb62096f8017e2fb61a5aa6acd4ed29e535765111568d52c443f134212fa8c8 + ghcr.io/wolfi-dev/sdk:latest@sha256:5f6c9819e4e88377441cced10084c9e1505f091e643520bcf690eed66a966b64 @rm "$(TMP_REPOSITORIES_FILE)" @rmdir "$(TMP_REPOSITORIES_DIR)"