Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Support reproducible builds with SOURCE_DATE_EPOCH

Aberta
#307 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
52/100
Tipo de issue
Funcionalidade
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
docker, github-actions
Domínio
build-system, ci-cd

Direção de pesquisa

Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Description
Problem

Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:

  • No input sets SOURCE_DATE_EPOCH for the build step. Passing it through build-args works for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout.
  • File timestamps inside the layers aren't rewritten. That needs rewrite-timestamp=true on the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it.
  • With set-meta-labels / set-meta-annotations, org.opencontainers.image.created gets the build time, because metadata-action uses the current date, even when SOURCE_DATE_EPOCH is set.

So two builds of the same commit always end up with different layer and image digests.

Proposal

A source-date-epoch input for build.yml (and bake.yml) that:

  1. sets SOURCE_DATE_EPOCH for the build step;
  2. adds rewrite-timestamp=true to the image (and local) output;
  3. uses the same time for the org.opencontainers.image.created label and annotation when set-meta-labels / set-meta-annotations are on.

It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.

Alternatives considered
  • build-args: SOURCE_DATE_EPOCH=… plus overriding meta-labels / meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.
  • Using docker/build-push-action directly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
Linguagem predominante
Sem dados de linguagem
Estrelas
87
Forks
23
Merge médio
5d 47min
PRs com merge (30d)
17

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de docker/github-builder

Todas as issues de docker/github-builder

Issues semelhantes

Mais issues de Build System

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.