From 97520b6d8341935d05dbfc8d67610f88fd0b31ef Mon Sep 17 00:00:00 2001 From: rawlingsj Date: Wed, 20 Sep 2023 09:16:07 +0000 Subject: [PATCH] Update images digests --- .github/workflows/build-world.yaml | 2 +- .github/workflows/build.yaml | 4 ++-- .github/workflows/ci-build.yaml | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build-world.yaml b/.github/workflows/build-world.yaml index 0355d879ac0..8f798842b68 100644 --- a/.github/workflows/build-world.yaml +++ b/.github/workflows/build-world.yaml @@ -23,7 +23,7 @@ jobs: # permissions: container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:495b0a1902724fcedff7f73f1e3a1d58600f7d3badef8c4b6661afcf2116746f + image: ghcr.io/wolfi-dev/sdk:latest@sha256:303c48da112a55bb884dd035a7cfef35b24528aca99e9a2223bb0170183c39ab # TODO: Deprivilege options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 656538dd730..644f2860fab 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -29,7 +29,7 @@ jobs: # permissions: container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:495b0a1902724fcedff7f73f1e3a1d58600f7d3badef8c4b6661afcf2116746f + image: ghcr.io/wolfi-dev/sdk:latest@sha256:303c48da112a55bb884dd035a7cfef35b24528aca99e9a2223bb0170183c39ab # TODO: Deprivilege options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined @@ -102,7 +102,7 @@ jobs: container: # NOTE: This step only signs and uploads, so it doesn't need any privileges - image: ghcr.io/wolfi-dev/sdk:latest@sha256:495b0a1902724fcedff7f73f1e3a1d58600f7d3badef8c4b6661afcf2116746f + image: ghcr.io/wolfi-dev/sdk:latest@sha256:303c48da112a55bb884dd035a7cfef35b24528aca99e9a2223bb0170183c39ab steps: - uses: actions/checkout@v3 diff --git a/.github/workflows/ci-build.yaml b/.github/workflows/ci-build.yaml index 8bd661f0c5b..326b034e14d 100644 --- a/.github/workflows/ci-build.yaml +++ b/.github/workflows/ci-build.yaml @@ -27,7 +27,7 @@ jobs: run: | # Copy wolfictl out of the wolfictl image and onto PATH TMP=$(mktemp -d) - docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:495b0a1902724fcedff7f73f1e3a1d58600f7d3badef8c4b6661afcf2116746f -c "cp /usr/bin/wolfictl /out" + docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:303c48da112a55bb884dd035a7cfef35b24528aca99e9a2223bb0170183c39ab -c "cp /usr/bin/wolfictl /out" echo "$TMP" >> $GITHUB_PATH # Assuming that we have a list of changed files such as `foo.yaml` and `bar.yaml`, this @@ -55,7 +55,7 @@ jobs: runs-on: wolfi-builder-spot-${{ matrix.arch }} needs: changes container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:495b0a1902724fcedff7f73f1e3a1d58600f7d3badef8c4b6661afcf2116746f + image: ghcr.io/wolfi-dev/sdk:latest@sha256:303c48da112a55bb884dd035a7cfef35b24528aca99e9a2223bb0170183c39ab options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --security-opt seccomp=unconfined --security-opt apparmor:unconfined