Support reproducible builds with SOURCE_DATE_EPOCH
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 52/100
- Issue 類型
- 功能
- 描述清晰度
- 基本清楚
- 活躍度
- 活躍
- 技術堆疊
- docker, github-actions
- 領域
- build-system, ci-cd
研究方向
Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.
由索引模型根據 Issue 內容生成。
描述
Description
Problem
Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:
- No input sets
SOURCE_DATE_EPOCHfor the build step. Passing it throughbuild-argsworks for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout. - File timestamps inside the layers aren't rewritten. That needs
rewrite-timestamp=trueon the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it. - With
set-meta-labels/set-meta-annotations,org.opencontainers.image.createdgets the build time, because metadata-action uses the current date, even whenSOURCE_DATE_EPOCHis set.
So two builds of the same commit always end up with different layer and image digests.
Proposal
A source-date-epoch input for build.yml (and bake.yml) that:
- sets
SOURCE_DATE_EPOCHfor the build step; - adds
rewrite-timestamp=trueto theimage(andlocal) output; - uses the same time for the
org.opencontainers.image.createdlabel and annotation whenset-meta-labels/set-meta-annotationsare on.
It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.
Alternatives considered
build-args: SOURCE_DATE_EPOCH=…plus overridingmeta-labels/meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.- Using
docker/build-push-actiondirectly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
- 主要語言
- 沒有語言資料
- 星號
- 87
- 分支
- 23
- 平均合併
- 5 天 47 分鐘
- 30 天內合併 PR
- 17
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
docker/github-builder 的其他 Issue
-
難度 4/5 3-5 天 新手友好度 52/100
docker/github-builder#251 ·
維護者通常 1 天內回覆
-
難度 3/5 1-2 天 新手友好度 68/100
docker/github-builder#209 ·
維護者通常 1 天內回覆
-
kind/enhancement
難度 3/5 1-2 天 新手友好度 65/100
docker/github-builder#207 · 1 則留言 ·
維護者通常 1 天內回覆
-
kind/enhancement status/triage
難度 5/5 一週以上 新手友好度 25/100
docker/github-builder#203 · 1 則留言 ·
維護者通常 1 天內回覆
-
status/triage
難度 4/5 3-5 天 新手友好度 45/100
docker/github-builder#193 · 2 則留言 ·
維護者通常 1 天內回覆
查看 docker/github-builder 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 78/100
JoviDeCroock/pracht#432 ·
維護者通常 1 天內回覆
-
fix(ci): check-changed-skills.sh fails a stale branch on skills only main changed可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉good first issue needs-triage priority: medium
難度 2/5 1-3 小時 新手友好度 72/100
melodic-software/claude-code-plugins#7014 · 1 則留言 ·
維護者通常 1 天內回覆
-
[Bug]: atlauncher fails to install due to invalid requires (libpulseaudio, libudev)可能已有人在做 @Owen-sz 今天認領。 未關閉
難度 2/5 1-3 小時 新手友好度 84/100
維護者通常 1 天內回覆
-
chore(build): TxCoordinator.cpp uses the deprecated shared_ptr atomic free functions可能已有人在做 @w5jwp 今天認領。 未關閉
難度 1/5 1 小時以內 新手友好度 84/100
aethersdr/AetherSDR#6368 · 1 則留言 ·
維護者通常 1 天內回覆
-
Typings import `react` and `react-dom`, but `@types/react` and `@types/react-dom` are not declared as peer dependencies可能已有人在做 @lazerg 今天認領。 未關閉react
難度 2/5 1-3 小時 新手友好度 78/100
維護者通常 1 天內回覆