Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Support reproducible builds with SOURCE_DATE_EPOCH

Aperta
#307 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
52/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
docker, github-actions

Direzione di ricerca

Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Description
Problem

Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:

  • No input sets SOURCE_DATE_EPOCH for the build step. Passing it through build-args works for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout.
  • File timestamps inside the layers aren't rewritten. That needs rewrite-timestamp=true on the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it.
  • With set-meta-labels / set-meta-annotations, org.opencontainers.image.created gets the build time, because metadata-action uses the current date, even when SOURCE_DATE_EPOCH is set.

So two builds of the same commit always end up with different layer and image digests.

Proposal

A source-date-epoch input for build.yml (and bake.yml) that:

  1. sets SOURCE_DATE_EPOCH for the build step;
  2. adds rewrite-timestamp=true to the image (and local) output;
  3. uses the same time for the org.opencontainers.image.created label and annotation when set-meta-labels / set-meta-annotations are on.

It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.

Alternatives considered
  • build-args: SOURCE_DATE_EPOCH=… plus overriding meta-labels / meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.
  • Using docker/build-push-action directly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
Lingua principale
Nessun dato sulla lingua
Stelle
86
Fork
23
Merge medio
5g 47m
PR unite (30g)
17

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di docker/github-builder

Tutte le issue di docker/github-builder

Issue simili

Altre issue su Build System

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.