Azure / Azure/cli

Pin Docker image to a specific SHA

Open
#201 0 comments 0 reactions 1 assignee Claimed by @wangzelin007 View on GitHub
need-to-triage
Dominant language
TypeScript
Stars
168
Forks
80
PR merge metrics
No merged PRs in 30d

Description

Docker allows specifying a digest when pulling images using the `:@sha256:` syntax. This allows guarantees reproducibility and helps prevent supply chain attacks.

When using this action, it is currently possible to pin the Docker image to a specific version using the `azcliversion` input, but because of [the extra validation](https://github.com/Azure/cli/blob/9eb25b8360668fb0ecbafa808d40e2197b2f5f52/src/main.ts#L96) it is not possible to suffix version numbers with a SHA256 digest.

The action should detect if such a prefix is present and strip it before checking the validity of the version number (but still use it when pulling the image).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.