Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Support reproducible builds with SOURCE_DATE_EPOCH

未關閉
#307 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
52/100
Issue 類型
功能
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
docker, github-actions

研究方向

Start with .github/workflows/build.yml, especially the output construction at the referenced v1.17.0 line 803, and inspect the corresponding bake.yml workflow and metadata-action inputs. Trace how workflow inputs reach the build step, image/local outputs, and metadata labels or annotations. Done means both workflows support the proposed epoch behavior, including commit, and builds use consistent timestamps for layers and created metadata.

由索引模型根據 Issue 內容生成。

描述

Description
Problem

Docker's reproducible builds guide for GitHub Actions recommends setting SOURCE_DATE_EPOCH, for example to the commit time (git log -1 --pretty=%ct), on the build step. With the build reusable workflow, there's currently no way to get a reproducible image:

  • No input sets SOURCE_DATE_EPOCH for the build step. Passing it through build-args works for the image config and history timestamps, because BuildKit reads it as a build arg too. But the caller has to compute the commit time in a separate job, since the reusable workflow builds from the Git context without a checkout.
  • File timestamps inside the layers aren't rewritten. That needs rewrite-timestamp=true on the image exporter (BuildKit docs). The workflow builds the output string itself (build.yml#L803 at v1.17.0), so callers can't add it.
  • With set-meta-labels / set-meta-annotations, org.opencontainers.image.created gets the build time, because metadata-action uses the current date, even when SOURCE_DATE_EPOCH is set.

So two builds of the same commit always end up with different layer and image digests.

Proposal

A source-date-epoch input for build.yml (and bake.yml) that:

  1. sets SOURCE_DATE_EPOCH for the build step;
  2. adds rewrite-timestamp=true to the image (and local) output;
  3. uses the same time for the org.opencontainers.image.created label and annotation when set-meta-labels / set-meta-annotations are on.

It would help most if the input could also take the commit time directly, for example source-date-epoch: commit, since the workflow already knows which commit it builds and callers wouldn't need an extra job for it.

Alternatives considered
  • build-args: SOURCE_DATE_EPOCH=… plus overriding meta-labels / meta-annotations: fixes the metadata timestamps, but not the layer contents, so the digests still differ.
  • Using docker/build-push-action directly: works, but gives up what the reusable workflow provides (distributed native builds, signed cache, signed provenance).
主要語言
沒有語言資料
星號
87
分支
23
平均合併
5 天 47 分鐘
30 天內合併 PR
17

環境準備

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

docker/github-builder 的其他 Issue

查看 docker/github-builder 的全部 Issue

相似的 Issue

更多 Build System Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。