diff --git a/.github/workflows/push-image.yaml b/.github/workflows/push-image.yaml new file mode 100644 index 0000000..9dbca5d --- /dev/null +++ b/.github/workflows/push-image.yaml @@ -0,0 +1,47 @@ +name: Push image to Docker Hub + +on: + release: + types: [published] + +env: + REGISTRY: docker.io + IMAGE_NAME: ${{ github.repository }} + +jobs: + push_to_registry: + runs-on: ubuntu-latest + permissions: + packages: write + contents: read + attestations: write + id-token: write + steps: + - name: Get current date + id: date + run: echo "NOW=$(date +'%y.%-m.%-d')" >> $GITHUB_ENV + + - uses: actions/checkout@v4 + + - name: Login in to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ secrets.DOCKER_USR }} + password: ${{ secrets.DOCKER_PAT }} + + - name: Build and push + uses: docker/build-push-action@v5 + id: push + with: + context: . + push: true + tags: | + ${{ env.IMAGE_NAME }}:latest + ${{ env.IMAGE_NAME }}:${{ env.NOW }} + + - name: Generate artifact attestation + uses: actions/attest-build-provenance@v1 + with: + subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}} + subject-digest: ${{ steps.push.outputs.digest }} + push-to-registry: true