Support reproducible builds with SOURCE_DATE_EPOCH
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 52/100
- Tipo de issue
- Funcionalidade
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- docker, github-actions
- Domínio
- build-system, ci-cd
Direção de pesquisa
Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Description
Problem
Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:
- No input sets
SOURCE_DATE_EPOCHfor the build step. Passing it throughbuild-argsworks for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout. - File timestamps inside the layers aren't rewritten. That needs
rewrite-timestamp=trueon the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it. - With
set-meta-labels/set-meta-annotations,org.opencontainers.image.createdgets the build time, because metadata-action uses the current date, even whenSOURCE_DATE_EPOCHis set.
So two builds of the same commit always end up with different layer and image digests.
Proposal
A source-date-epoch input for build.yml (and bake.yml) that:
- sets
SOURCE_DATE_EPOCHfor the build step; - adds
rewrite-timestamp=trueto theimage(andlocal) output; - uses the same time for the
org.opencontainers.image.createdlabel and annotation whenset-meta-labels/set-meta-annotationsare on.
It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.
Alternatives considered
build-args: SOURCE_DATE_EPOCH=…plus overridingmeta-labels/meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.- Using
docker/build-push-actiondirectly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
- Linguagem predominante
- Sem dados de linguagem
- Estrelas
- 87
- Forks
- 23
- Merge médio
- 5d 47min
- PRs com merge (30d)
- 17
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de docker/github-builder
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 52/100
docker/github-builder#251 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 68/100
docker/github-builder#209 ·
Mantenedores costumam responder em até 1 dia
-
kind/enhancement
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 65/100
docker/github-builder#207 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
kind/enhancement status/triage
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 25/100
docker/github-builder#203 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
status/triage
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 45/100
docker/github-builder#193 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
Todas as issues de docker/github-builder
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
JoviDeCroock/pracht#432 ·
Mantenedores costumam responder em até 1 dia
-
fix(ci): check-changed-skills.sh fails a stale branch on skills only main changedTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertagood first issue needs-triage priority: medium
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
melodic-software/claude-code-plugins#7014 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
[Bug]: atlauncher fails to install due to invalid requires (libpulseaudio, libudev)Talvez já em andamento @Owen-sz assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
Mantenedores costumam responder em até 1 dia
-
chore(build): TxCoordinator.cpp uses the deprecated shared_ptr atomic free functionsTalvez já em andamento @w5jwp assumiu hoje. Aberta
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 84/100
aethersdr/AetherSDR#6368 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Typings import `react` and `react-dom`, but `@types/react` and `@types/react-dom` are not declared as peer dependenciesTalvez já em andamento @lazerg assumiu hoje. Abertareact
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia