Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Support reproducible builds with SOURCE_DATE_EPOCH

Ouverte
#307 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
52/100
Type d'issue
Fonctionnalité
Clarté
Plutôt claire
Activité
Active
Stack technique
docker, github-actions
Domaine
build-system, ci-cd

Piste de recherche

Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

Description
Problem

Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:

  • No input sets SOURCE_DATE_EPOCH for the build step. Passing it through build-args works for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout.
  • File timestamps inside the layers aren't rewritten. That needs rewrite-timestamp=true on the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it.
  • With set-meta-labels / set-meta-annotations, org.opencontainers.image.created gets the build time, because metadata-action uses the current date, even when SOURCE_DATE_EPOCH is set.

So two builds of the same commit always end up with different layer and image digests.

Proposal

A source-date-epoch input for build.yml (and bake.yml) that:

  1. sets SOURCE_DATE_EPOCH for the build step;
  2. adds rewrite-timestamp=true to the image (and local) output;
  3. uses the same time for the org.opencontainers.image.created label and annotation when set-meta-labels / set-meta-annotations are on.

It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.

Alternatives considered
  • build-args: SOURCE_DATE_EPOCH=… plus overriding meta-labels / meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.
  • Using docker/build-push-action directly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
Langage dominant
Aucune donnée de langage
Étoiles
86
Forks
23
Merge moyen
5 j 47 min
PR mergées (30 j)
17

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de docker/github-builder

Toutes les issues de docker/github-builder

Issues similaires

Plus d'issues Build System

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.