A tag is a mutable pointer. `actions/checkout@v7` is whatever the publisher last moved v7 to, so using one is not trusting the version that was reviewed -- it is trusting every future version, including whatever is pushed by whoever compromises the publisher's account. That is the shape of the tj-actions/changed-files compromise: no repository changed a line, the tags moved underneath them, and the action began dumping runner memory to the logs. Each `uses:` now carries the full 40-character SHA with its release in a trailing comment. Read the comment for the version; the SHA is what runs. Dependabot already covers github-actions weekly and updates both halves together, so keeping current costs nothing. The dataaxiom cleanup action was already pinned -- it is handed `packages: write` and deletes things, so it was worth doing early -- and only picks up the trailing-version convention here. Its comment loses the "rather than a moving major tag" framing, which is no longer what makes it different from its neighbors now that they are all pinned too. The two `uses: ./.github/workflows/...` entries are local paths, not actions: they always resolve within the commit already running and there is no SHA to pin.
70 lines
3.1 KiB
YAML
70 lines
3.1 KiB
YAML
# Prune old image versions from GHCR.
|
|
#
|
|
# Releases are kept forever -- they carry no assets and their generated notes
|
|
# are this project's only changelog, so deleting one destroys history that
|
|
# cannot be reconstructed for nothing saved. Images are the opposite: a
|
|
# multi-arch build a week, and the by-digest push in publish.yml leaves two
|
|
# untagged per-architecture manifests behind each time on top of the tagged
|
|
# index. Those accumulate and nobody wants fifty of them.
|
|
#
|
|
# THE FOOTGUN: the obvious tool for this -- delete-package-versions with
|
|
# `delete-only-untagged-versions` -- will happily delete the per-architecture
|
|
# manifests that a multi-arch tag points *at*, because they are untagged by
|
|
# design. Nothing appears to break: the tag still exists, and pulls simply
|
|
# start failing for one architecture. This action understands manifest lists
|
|
# and will not orphan a retained index, and `validate` re-checks every
|
|
# multi-arch manifest against the registry afterwards.
|
|
#
|
|
# Separate from publish.yml, and dispatchable on its own, so `dry_run` can show
|
|
# exactly what would be deleted without rebuilding and re-pushing an image to
|
|
# find out.
|
|
name: Prune images
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
dry_run:
|
|
type: boolean
|
|
default: false
|
|
workflow_dispatch:
|
|
inputs:
|
|
dry_run:
|
|
description: "List what would be deleted, delete nothing"
|
|
type: boolean
|
|
default: true
|
|
|
|
jobs:
|
|
prune:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
packages: write
|
|
steps:
|
|
# The only third-party action here that is not published by GitHub or
|
|
# Docker, and the one with the most to lose: it is handed
|
|
# `packages: write` and its whole job is deletion, so a ref repointed at
|
|
# something else -- by a compromise or a mistake upstream -- is a bad
|
|
# day. It was pinned to a commit long before the rest of them were.
|
|
- uses: dataaxiom/ghcr-cleanup-action@d52806a0dc70b430571a37da1fde39733ffd640f # v1.2.2
|
|
with:
|
|
owner: Coffey-Labs
|
|
package: ihasmail
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
# Ten weekly releases is roughly a quarter of history, which is more
|
|
# than enough to roll back to and far less than the year's worth that
|
|
# would otherwise pile up. Older *releases* stay either way; this
|
|
# only removes the images.
|
|
keep-n-tagged: 10
|
|
# Belt and braces on top of the action's own manifest awareness:
|
|
# `latest` is never a candidate for deletion under any counting.
|
|
exclude-tags: latest
|
|
delete-untagged: true
|
|
# Sweeps the wreckage of a half-failed run: an index whose platform
|
|
# images did not all land, and referrers whose parent is gone.
|
|
delete-partial-images: true
|
|
delete-orphaned-images: true
|
|
# Checks every remaining multi-architecture manifest still resolves
|
|
# in the registry. This is the step that would catch the footgun
|
|
# above rather than leaving a reader to discover it on `docker pull`.
|
|
validate: true
|
|
dry-run: ${{ inputs.dry_run }}
|