Pin Docker image to a specific SHA
- Dominant language
- TypeScript
- Stars
- 168
- Forks
- 80
- PR merge metrics
- No merged PRs in 30d
Description
Docker allows specifying a digest when pulling images using the `:@sha256:` syntax. This allows guarantees reproducibility and helps prevent supply chain attacks.
When using this action, it is currently possible to pin the Docker image to a specific version using the `azcliversion` input, but because of [the extra validation](https://github.com/Azure/cli/blob/9eb25b8360668fb0ecbafa808d40e2197b2f5f52/src/main.ts#L96) it is not possible to suffix version numbers with a SHA256 digest.
The action should detect if such a prefix is present and strip it before checking the validity of the version number (but still use it when pulling the image).
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.