Trivy Compliant, Action full SHA, cat file warnnings

This commit is contained in:
Samuel Huang
2024-10-05 21:59:14 +10:00
parent 65db23b969
commit 61799ba532
3 changed files with 16 additions and 17 deletions

View File

@@ -15,18 +15,18 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@v2 uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
with: with:
ref: ${{ github.ref }} ref: ${{ github.ref }}
- -
name: Set up QEMU name: Set up QEMU
uses: docker/setup-qemu-action@v1 uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
with: with:
platforms: all platforms: all
- -
name: Set up Docker Buildx name: Set up Docker Buildx
id: buildx id: buildx
uses: docker/setup-buildx-action@v1 uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
with: with:
version: latest version: latest
- -
@@ -34,13 +34,13 @@ jobs:
run: echo ${{ steps.buildx.outputs.platforms }} run: echo ${{ steps.buildx.outputs.platforms }}
- -
name: Login to DockerHub name: Login to DockerHub
uses: docker/login-action@v1 uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
with: with:
username: ${{ secrets.DOCKERHUB_USERNAME }} username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }} password: ${{ secrets.DOCKERHUB_TOKEN }}
- -
name: Build and push multi-arch dev name: Build and push multi-arch dev
uses: docker/build-push-action@v2 uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
with: with:
context: . context: .
file: ./Dockerfile file: ./Dockerfile

View File

@@ -15,18 +15,18 @@ jobs:
steps: steps:
- -
name: Checkout name: Checkout
uses: actions/checkout@v2 uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
with: with:
ref: ${{ github.ref }} ref: ${{ github.ref }}
- -
name: Set up QEMU name: Set up QEMU
uses: docker/setup-qemu-action@v1 uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
with: with:
platforms: all platforms: all
- -
name: Set up Docker Buildx name: Set up Docker Buildx
id: buildx id: buildx
uses: docker/setup-buildx-action@v1 uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
with: with:
version: latest version: latest
- -
@@ -34,13 +34,13 @@ jobs:
run: echo ${{ steps.buildx.outputs.platforms }} run: echo ${{ steps.buildx.outputs.platforms }}
- -
name: Login to DockerHub name: Login to DockerHub
uses: docker/login-action@v1 uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
with: with:
username: ${{ secrets.DOCKERHUB_USERNAME }} username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }} password: ${{ secrets.DOCKERHUB_TOKEN }}
- -
name: Build and push multi-arch latest name: Build and push multi-arch latest
uses: docker/build-push-action@v2 uses: docker/build-push-action@4f58ea79222b3b9dc2c8bbdd6debcef730109a75 # v6.9.0
with: with:
context: . context: .
file: ./Dockerfile file: ./Dockerfile

View File

@@ -180,13 +180,12 @@ do
ESC_CERTFILE=$(printf '%s\n' "${fullchain}" | sed -e 's/[]\/$*.^[]/\\&/g') ESC_CERTFILE=$(printf '%s\n' "${fullchain}" | sed -e 's/[]\/$*.^[]/\\&/g')
ESC_PRVKEYFILE=$(printf '%s\n' "${prvkey}" | sed -e 's/[]\/$*.^[]/\\&/g') ESC_PRVKEYFILE=$(printf '%s\n' "${prvkey}" | sed -e 's/[]\/$*.^[]/\\&/g')
cat "${SITE_TPL}" \ cp -a "${SITE_TPL}" "${site_domain}.conf"
| sed "s/CERTFILE/${ESC_CERTFILE}/g" \ sed -i "s/CERTFILE/${ESC_CERTFILE}/g" "${site_domain}.conf"
| sed "s/PRVKEYFILE/${ESC_PRVKEYFILE}/g" \ sed -i "s/PRVKEYFILE/${ESC_PRVKEYFILE}/g" "${site_domain}.conf"
| sed "s/NGDOMAIN/${site_domain}/g" \ sed -i "s/NGDOMAIN/${site_domain}/g" "${site_domain}.conf"
| sed "s/NGPORT/${port}/g" \ sed -i "s/NGPORT/${port}/g" "${site_domain}.conf"
| sed "s/NGPROTOCOL/${NGPROTOCOL}/g" \ sed -i "s/NGPROTOCOL/${NGPROTOCOL}/g" "${site_domain}.conf"
>"${site_domain}.conf"
# Applying proxy log format instead of main format when --ng-server proxy_pass was set # Applying proxy log format instead of main format when --ng-server proxy_pass was set
if [ -n "${NGPROTOCOL}" ]; then if [ -n "${NGPROTOCOL}" ]; then
sed -i '/access_log/s/main/proxy/' "${site_domain}.conf" sed -i '/access_log/s/main/proxy/' "${site_domain}.conf"