i guess we rawdogging digests over here
Some checks failed
ci/woodpecker/push/scans Pipeline was successful
ci/woodpecker/push/build Pipeline failed

This commit is contained in:
Radek Goláň jr. 2024-10-31 10:49:23 +01:00
parent 63e72559be
commit b9616bb19e
Signed by: shield
GPG Key ID: D86423BFC31F3591

View File

@ -63,10 +63,14 @@ steps:
from_secret: registry_username
DOCKER_PASS:
from_secret: registry_password
when:
- event: push
branch: main
commands:
- dnf install -y jq
- skopeo inspect --raw docker://dev.shielddagger.com/shielddagger/heimdall:latest | jq .'manifests[] | select(.platform.architecture=="arm64").digest' > digest-arm64
- skopeo inspect --raw docker://dev.shielddagger.com/shielddagger/heimdall:latest | jq .'manifests[] | select(.platform.architecture=="amd64").digest' > digest-amd64
- skopeo login --username $DOCKER_USER --password $DOCKER_PASS
- skopeo inspect --raw docker://dev.shielddagger.com/opensource/discord-notifier:latest | jq .'manifests[] | select(.platform.architecture=="arm64").digest' > digest-arm64
- skopeo inspect --raw docker://dev.shielddagger.com/opensource/discord-notifier:latest | jq .'manifests[] | select(.platform.architecture=="amd64").digest' > digest-amd64
- name: image-scan
image: aquasec/trivy
environment: