Pin Docker image to a specific SHA
- Langage dominant
- TypeScript
- Étoiles
- 168
- Forks
- 80
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
Docker allows specifying a digest when pulling images using the `:@sha256:` syntax. This allows guarantees reproducibility and helps prevent supply chain attacks.
When using this action, it is currently possible to pin the Docker image to a specific version using the `azcliversion` input, but because of [the extra validation](https://github.com/Azure/cli/blob/9eb25b8360668fb0ecbafa808d40e2197b2f5f52/src/main.ts#L96) it is not possible to suffix version numbers with a SHA256 digest.
The action should detect if such a prefix is present and strip it before checking the validity of the version number (but still use it when pulling the image).
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.