Skip to content

Commit

Permalink
Merge branch 'main' into tailscale_extra
Browse files Browse the repository at this point in the history
Signed-off-by: Gaël Donval <[email protected]>
  • Loading branch information
gdonval authored Nov 26, 2024
2 parents f179001 + c58771e commit 595623d
Show file tree
Hide file tree
Showing 2,632 changed files with 65,773 additions and 17,430 deletions.
2 changes: 1 addition & 1 deletion .github/actions/docker-run/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ inputs:
required: true
image:
description: "The image to use"
default: "ghcr.io/wolfi-dev/sdk:latest@sha256:41afbe0864023cc9fb7dda378e831fcb4ae56b88fb36475a4e28a5555c0f71a5"
default: "ghcr.io/wolfi-dev/sdk:latest@sha256:98d8669d2eb9c8d23984fa2f55a272b67a04b4bfd132c714682c4fd716a3d7be"
required: false
workdir:
description: "The images working directory"
Expand Down
8 changes: 8 additions & 0 deletions .github/chainguard/ci-apk-add.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
issuer: https://accounts.google.com

# staging-enforce: ci-apk-add-yoc7io2zgcz1c4cipdy@staging-enforce-cd1e.iam.gserviceaccount.com (115990274270281280608)
# prod-enforce: ci-apk-add-17s907efi2d0465e6qe@prod-enforce-fabc.iam.gserviceaccount.com (117483518394993895135)
subject_pattern: "(115990274270281280608|117483518394993895135)"

permissions:
checks: write
8 changes: 8 additions & 0 deletions .github/chainguard/ci-diff-report.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
issuer: https://accounts.google.com

# staging-enforce: ci-diff-report-bz8uqwvcxxpc4kk@staging-enforce-cd1e.iam.gserviceaccount.com (104301860717534032690)
# prod-enforce: ci-diff-report-7g7cc3gw9zrgnb8@prod-enforce-fabc.iam.gserviceaccount.com (110787029573344269306)
subject_pattern: "(104301860717534032690|110787029573344269306)"

permissions:
checks: write
9 changes: 9 additions & 0 deletions .github/chainguard/ci-mal-report.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
issuer: https://accounts.google.com

# staging-enforce: ci-mal-report-le3mjq3jgc92p8dq@staging-enforce-cd1e.iam.gserviceaccount.com (118407883719299185923)
# prod-enforce: ci-mal-report-17r0pitrh9qbqewe@prod-enforce-fabc.iam.gserviceaccount.com (103832439759204749706)
subject_pattern: "(118407883719299185923|103832439759204749706)"

permissions:
checks: write
pull_requests: write # to add labels
8 changes: 8 additions & 0 deletions .github/chainguard/ci-sbom-validity.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
issuer: https://accounts.google.com

# staging-enforce: ci-sbom-validity-zsn7d1bnadvrq@staging-enforce-cd1e.iam.gserviceaccount.com (113934452987096951720)
# prod-enforce: ci-sbom-validity-s42iysnurdqrc@prod-enforce-fabc.iam.gserviceaccount.com (101446196544792515300)
subject_pattern: "(113934452987096951720|101446196544792515300)"

permissions:
checks: write
8 changes: 8 additions & 0 deletions .github/chainguard/ci-so-check.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
issuer: https://accounts.google.com

# staging-enforce: ci-so-check-stvn49i5f66mni64gt@staging-enforce-cd1e.iam.gserviceaccount.com (103377873370411205770)
# prod-enforce: ci-so-check-pitbc0wzwgefx2btsy@prod-enforce-fabc.iam.gserviceaccount.com (114009508504016091101)
subject_pattern: "(103377873370411205770|114009508504016091101)"

permissions:
checks: write
9 changes: 9 additions & 0 deletions .github/chainguard/lifecycle-build-failures.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
issuer: https://accounts.google.com

# staging: ai-build-failure0b6i89pk2j7u2f@staging-enforce-cd1e.iam.gserviceaccount.com
# prod: ai-build-failurexiszcy26s41ogv@prod-enforce-fabc.iam.gserviceaccount.com
subject_pattern: "(117815286528662951292|110160732638115110864)"

permissions:
contents: read
pull_requests: write
11 changes: 11 additions & 0 deletions .github/chainguard/lifecycle-eol-cve-triage.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
issuer: https://accounts.google.com

# eol-cve-triage-ukbn1lwavqhiozn@prod-enforce-fabc.iam.gserviceaccount.com
# staging-enforce: eol-cve-triage-tvw0l8pfys6ar7e@staging-enforce-cd1e.iam.gserviceaccount.com
subject_pattern: "(112057240867162796263|101250437316036373382)"

permissions:
contents: read
actions: read
checks: read
pull_requests: read
9 changes: 0 additions & 9 deletions .github/chainguard/lifecycle-gpt.sts.yaml

This file was deleted.

4 changes: 2 additions & 2 deletions .github/chainguard/lifecycle-package-update-check.sts.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
issuer: https://accounts.google.com

# bot-[email protected]
subject: "101210949108710137698"
# update-check[email protected]
subject: "111168679734430510548"

permissions:
contents: read
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/auto-approve.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,12 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
uses: step-security/harden-runner@0080882f6c36860b6ba35c610c98ce87d4e2f26f # v2.10.2
with:
egress-policy: audit

- name: Check out repository code
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- run: |
./scripts/auto-approve-pr.sh ${{ github.repository }}
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/backfill.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,18 +13,18 @@ jobs:
contents: read

steps:
- uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- uses: google-github-actions/auth@8254fb75a33b976a221574d287e93919e6a36f70 # v2.1.6
- uses: google-github-actions/auth@6fc4af4b145ae7821d527454aa9bd537d1f2dc5f # v2.1.7
with:
workload_identity_provider: "projects/618116202522/locations/global/workloadIdentityPools/prod-shared-e350/providers/prod-shared-gha"
service_account: "[email protected]"

- uses: google-github-actions/setup-gcloud@f0990588f1e5b5af6827153b93673613abdc6ec7 # v2.1.1
- uses: google-github-actions/setup-gcloud@6189d56e4096ee891640bb02ac264be376592d6a # v2.1.2
with:
project_id: "prod-images-c6e5"

- uses: chainguard-dev/setup-chainctl@598499528905f95b94e62e4831cf42035e768933 # v0.2.3
- uses: chainguard-dev/setup-chainctl@8d93dcbef466d3cf3533f67084f52eb74ef9d262 # v0.2.4
with:
# Managed here:
# https://github.com/chainguard-dev/mono/blob/main/env/chainguard-images/iac/wolfi-os-pusher.tf
Expand Down Expand Up @@ -78,7 +78,7 @@ jobs:
done < backfill-packages.txt
done
- uses: rtCamp/action-slack-notify@4e5fb42d249be6a45a298f3c9543b111b02f7907 # v2.3.0
- uses: rtCamp/action-slack-notify@c33737706dea87cd7784c687dadc9adf1be59990 # v2.3.2
if: failure()
env:
SLACK_ICON: http://github.com/chainguard-dev.png?size=48
Expand Down
215 changes: 0 additions & 215 deletions .github/workflows/build-beta.yaml

This file was deleted.

Loading

0 comments on commit 595623d

Please sign in to comment.