Provenance issue with public repository
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 45/100
研究方向
從 .github/workflows/publish.yml 第 176 行附近以及固定在 v1.6.0 的 .github/workflows/build.yml 開始,然後將它們的建置設定與可正常運作的 docker buildx 指令進行比較。重現該工作流程,並使用 docker buildx imagetools 檢查產生的映像;當支援的設定或限制已確立,且 provenance 行為已被記錄或修正後,該 issue 即完成。
由索引模型根據 Issue 內容生成。
描述
Contributing guidelines
- I've read the contributing guidelines and wholeheartedly agree
I've found a bug, and:
- The documentation does not mention anything about my problem
- There are no open or closed issues that are related to my problem
Description
Hello,
My repository is public (https://github.com/nsphung/mcp-snowflake-server/blob/main/Dockerfile). And from my understanding, using docker/github-builder (docker/github-builder/.github/workflows/build.yml@7d2a02426d4b989616ba5aaee4e879afd4134b0d # v1.6.0), it should use docker/buildx provenance = mode=max,version=v1. But I don't have the expected results.
Expected behaviour
This is what I have without using docker/github-builder:
docker buildx imagetools inspect nsphung/mcp-snowflake-server-nsp:0.8.0 --format "{{ json .Provenance.SLSA }}"
# This one is working
This was build with:
docker buildx build \
--tag nsphung/mcp-snowflake-server-nsp:0.8.0 \
--sbom=true \
--attest type=provenance,mode=max,version=v1 \
.
Is there any way to have the same feature in docker/github-builder ? Or maybe I'm missing a configuration.
Actual behaviour
docker buildx imagetools inspect nsphung/mcp-snowflake-server-nsp:0.11.2 --format "{{ json .Provenance.SLSA }}"
null%
Here we can see null when inspecting for provenance.
Repository URL
https://github.com/nsphung/mcp-snowflake-server/tree/main
Workflow run URL
https://github.com/nsphung/mcp-snowflake-server/actions/runs/25457043001
YAML workflow
You can checkout the yaml at:
https://github.com/nsphung/mcp-snowflake-server/blob/main/.github/workflows/publish.yml#L176
Workflow logs
No response
BuildKit logs
Additional info
No response
- 主要語言
- 沒有語言資料
- 星號
- 86
- 分支
- 23
- 平均合併
- 5 天 47 分鐘
- 30 天內合併 PR
- 17
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
docker/github-builder 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 52/100
docker/github-builder#307 ·
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 52/100
docker/github-builder#251 ·
維護者通常 1 天內回覆
-
難度 3/5 1-2 天 新手友好度 68/100
docker/github-builder#209 ·
維護者通常 1 天內回覆
-
kind/enhancement
難度 3/5 1-2 天 新手友好度 65/100
docker/github-builder#207 · 1 則留言 ·
維護者通常 1 天內回覆
-
kind/enhancement status/triage
難度 5/5 一週以上 新手友好度 25/100
docker/github-builder#203 · 1 則留言 ·
維護者通常 1 天內回覆
查看 docker/github-builder 的全部 Issue
相似的 Issue
-
Status: Untriaged
難度 1/5 1 小時以內 新手友好度 85/100
-
難度 2/5 1-3 小時 新手友好度 72/100
components-web-app/docs#195 ·
-
難度 2/5 1-3 小時 新手友好度 82/100
zerocracy/judges-action#2733 ·
維護者通常 8 天內回覆
-
windows-latest CI red on master: #2605 bundle-patch test breaks under CRLF checkout (dsh.bundle.patch.yml missing from .gitattributes eol=lf)可能重新可做 關聯的 PR 已關閉且未合併。 未關閉
難度 1/5 1 小時以內 新手友好度 72/100
ranxianglei/billion-context#2623 · 2 則留言 ·
維護者通常 1 天內回覆
-
dependencies feature github_actions good first issue
難度 2/5 1-3 小時 新手友好度 62/100
wemake-services/wemake-django-template#3149 ·
維護者通常 1 天內回覆