Skip to content

ci: publish secure multiarch releases - #7

Open
castrojo wants to merge 3 commits into
feat/fsdk-appliance-parityfrom
feat/fsdk-secure-releases
Open

castrojo wants to merge 3 commits into
feat/fsdk-appliance-parityfrom
feat/fsdk-secure-releases

Conversation

@castrojo

Copy link
Copy Markdown

Summary

  • run the full FSDK appliance gate on native amd64 and arm64 pull-request runners without registry credentials
  • make VERSION canonical and require a matching v<VERSION> tag before publication
  • publish an immutable annotated GHCR index with no mutable channel aliases
  • attach dual-platform SPDX SBOMs, keyless-sign the image and SBOM, publish GitHub provenance, and verify all evidence

Verification

  • just verify
  • actionlint .github/workflows/*.yml
  • bash -n tests/*.sh files/*.sh
  • canonical VERSION/binary/OCI-label equality check
  • local Podman release-label mutation smoke
  • git diff --check

The tag-only publish path was reviewed and linted but intentionally not executed; it writes a real immutable release.

Stacked on #6 (feat/fsdk-appliance-parity).

Assisted-by: GitHub Copilot GPT-5.6 via pi
Assisted-by: GitHub Copilot GPT-5.6 via pi
Assisted-by: GitHub Copilot GPT-5.6 via pi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant