-
Notifications
You must be signed in to change notification settings - Fork 2
92 lines (73 loc) · 3.25 KB
/
publish.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
name: Publish
on:
push:
branches:
- master
release:
types: [published]
env:
IMAGE_NAME: codeql
CONTAINER_REGISTRY_HOST: ghcr.io
jobs:
compile:
runs-on: ubuntu-latest
strategy:
matrix:
code_language: [none, cpp, csharp, csv, go, html, java, javascript, properties, python, xml]
steps:
- uses: actions/checkout@v2
- uses: FranzDiebold/github-env-vars-action@v2
- name: Log into registry
run: echo "${{ secrets.PAT }}" | docker login $CONTAINER_REGISTRY_HOST -u $CI_REPOSITORY_OWNER --password-stdin
- name: Set build variables
id: build
run: |
BRANCH=$(echo ${GITHUB_REF#refs/heads/})
IMAGE_ID=$CONTAINER_REGISTRY_HOST/$CI_REPOSITORY_OWNER/$IMAGE_NAME
# Change all uppercase to lowercase
IMAGE_ID=$(echo $IMAGE_ID | tr '[A-Z]' '[a-z]')
# Strip git ref prefix from version
VERSION=$(echo "${{ github.ref }}" | sed -e 's,.*/\(.*\),\1,')
# Strip "v" prefix from tag name
[[ "${{ github.ref }}" == "refs/tags/"* ]] && VERSION=$(echo $VERSION | sed -e 's/^v//')
[ "$VERSION" == "master" ] && VERSION=$(curl https://api.github.com/repos/github/codeql-cli-binaries/releases/latest | jq -r '.tag_name' | sed -e 's/^v//')
TAG="${{ matrix.code_language }}-$VERSION"
if [ "${{ matrix.code_language }}" == "none" ]; then
TAG="$VERSION"
fi
echo BRANCH=$BRANCH
echo IMAGE_ID=$IMAGE_ID
echo VERSION=$VERSION
echo TAG=$TAG
echo ::set-output name=branch::${BRANCH}
echo ::set-output name=image_id::${IMAGE_ID}
echo ::set-output name=version::${VERSION}
echo ::set-output name=tag::${TAG}
- name: Fetch cached image
run: >-
docker pull ${{ steps.build.outputs.image_id }}:${{ steps.build.outputs.tag }} || true
- name: Build image
run: >-
docker build .
--file Dockerfile
--tag $IMAGE_NAME
--cache-from ${{ steps.build.outputs.image_id }}:${{ steps.build.outputs.tag }}
--label "org.opencontainers.image.revision=$GITHUB_SHA"
--label "org.opencontainers.image.source=https://github.com/${{ github.repository }}"
--label "org.opencontainers.image.created=$(date -u +'%Y-%m-%dT%H:%M:%SZ')"
--label "org.opencontainers.image.description=CodeQL Docker for ${{ matrix.code_language }}"
--label "com.github.repo.dockerfile=Dockerfile"
--label "com.github.repo.branch=${{ steps.build.outputs.branch }}"
--build-arg CLI_VERSION=${{ steps.build.outputs.version }}
--build-arg CODE_LANGUAGE=${{ matrix.code_language }}
- name: Push image
run: |
docker tag $IMAGE_NAME ${{ steps.build.outputs.image_id }}:${{ steps.build.outputs.tag }}
if [ ${{ github.event_name }} == "release" ]; then
if [ ${{ matrix.code_language }} == "none" ]; then
docker tag $IMAGE_NAME ${{ steps.build.outputs.image_id }}:latest
else
docker tag $IMAGE_NAME ${{ steps.build.outputs.image_id }}:${{ matrix.code_language }}
fi
fi
docker push -a ${{ steps.build.outputs.image_id }}