Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
74 commits
Select commit Hold shift + click to select a range
2c0ac24
fix(desktop): stop the create-agent provider config probe from erasin…
tlongwell-block Aug 3, 2026
83a285f
ci(linux): enable mesh-llm feature in Linux release and canary builds…
tlongwell-block Aug 3, 2026
857e63c
Polish mobile composer and messaging UI (#3918)
klopez4212 Aug 3, 2026
be95a8a
fix(config-bridge): add harness-definition env tier and fix equal-val…
wpfleger96 Aug 3, 2026
f810a2f
fix(desktop): make OpenAI key re-enterable after first save in card m…
wpfleger96 Aug 3, 2026
5e0efb0
fix(desktop): disambiguate provider API key labels and annotate mint …
wpfleger96 Aug 3, 2026
f865c00
feat(desktop): show saved Run on settings when editing an agent (#4539)
tlongwell-block Aug 3, 2026
b0c6d6f
Add channel activity hover menu (#3935)
klopez4212 Aug 3, 2026
01c80aa
fix(desktop): save key backups to authorized path (#4022)
tellaho Aug 3, 2026
c1b88af
feat(desktop): improve channel template discovery (#4549)
wesbillman Aug 3, 2026
80315ac
fix(desktop): harden Windows installs against Defender block and orph…
wpfleger96 Aug 3, 2026
09c86c5
fix: report agent usage per provider round, not once per turn (#4545)
atishpatel Aug 3, 2026
44fa1e8
docs(release): align desktop handoff instructions (#3988)
wesbillman Aug 3, 2026
6de85fe
test(mobile): assert follow boundary semantics (#4559)
wesbillman Aug 3, 2026
651f637
chore(release): release Buzz Desktop version 0.5.4 (#4562)
wesbillman Aug 3, 2026
ce56e34
fix(mobile): recover stale relay sessions (#4372)
brow Aug 3, 2026
e1f6da7
ci: add guarded desktop release cache prewarm (#4575)
wesbillman Aug 3, 2026
5c98932
feat(desktop): make onboarding model defaults skippable (#3968)
tellaho Aug 3, 2026
d4a4570
fix(desktop): clarify inherited agent parallelism (#4010)
wesbillman Aug 3, 2026
7981597
fix(reactions): wrap long popover names (#3834)
tellaho Aug 3, 2026
027a74a
Polish Share Compute settings (#3735)
klopez4212 Aug 3, 2026
985cdcc
feat(agents): model-tuning parity in global Agent Defaults editor (#4…
wpfleger96 Aug 3, 2026
ede8d22
feat(mobile): bring channel menus to desktop parity (#3940)
tellaho Aug 3, 2026
b29c8cd
feat(desktop): redesign the Huddle experience (#4281)
klopez4212 Aug 4, 2026
d5da74e
feat(mobile): add channel scroll navigation (#4239)
tellaho Aug 4, 2026
b42b093
feat(mobile): sync per-group channel sorting (#4231)
tellaho Aug 4, 2026
631b05c
feat: ship Buzz Term (#4347)
tlongwell-block Aug 4, 2026
feccf4e
Polish mobile inbox and media flows (#4512)
klopez4212 Aug 4, 2026
ddcf0ae
fix(desktop): stop clipping focus ring on channel intro action cards …
iroiro147 Aug 4, 2026
f18a9cb
Defer desktop media uploads until send (#4522)
klopez4212 Aug 4, 2026
a5bf3c5
Refine desktop timeline activity presentation (#4582)
klopez4212 Aug 4, 2026
d0af845
Remove blur from Welcome composer guidance (#4691)
klopez4212 Aug 4, 2026
0542bc8
docs(nip-am): normative amendment — cache SHOULD/MUST + pricingIdenti…
wpfleger96 Aug 4, 2026
56003eb
docs(acp): explain per-channel session model in base prompt (#4729)
wpfleger96 Aug 4, 2026
d0d4acd
fix(desktop): show cached display names on startup (#3317)
TheSentinel454 Aug 4, 2026
540b589
Polish sidebar unread hierarchy (#4573)
klopez4212 Aug 4, 2026
f86dfc5
feat(desktop): surface config diff in restart-required badge (#3637)
wpfleger96 Aug 4, 2026
0afeac8
feat(desktop): persist sidebar observed-unread across webview reload …
wpfleger96 Aug 4, 2026
e1287c9
Refine community invite links (#4734)
klopez4212 Aug 4, 2026
0c33a8a
fix(agents): canonicalize stale persona harness pins (#4631)
wpfleger96 Aug 4, 2026
bc9e652
perf(relay): index channel-id lookups and skip trace-only reads (#4647)
jemiahw Aug 4, 2026
cb4a73e
Dock Buzz Term within channel workspace (#4724)
wesbillman Aug 4, 2026
e5efd04
fix(desktop): close reconnect gaps that previously required CMD+R (#4…
wesbillman Aug 4, 2026
7bee84d
fix(mobile): stop oversized read-state retry loop (#4595)
wesbillman Aug 4, 2026
5179726
fix(local-archive): default both archive settings to enabled (#4750)
wpfleger96 Aug 4, 2026
ce3cf3c
Polish Huddle voice controls (#4694)
klopez4212 Aug 4, 2026
8b8d86c
fix(desktop): integer-align custom reaction emoji (#4779)
kalvinnchau Aug 4, 2026
65f7a10
fix(desktop): wait for terminal frame before splash (#4781)
wesbillman Aug 4, 2026
7bcfe7e
fix(desktop): widen post-Enter timeouts in empty-edit-delete spec (#4…
wpfleger96 Aug 4, 2026
383d9e1
fix(ci): make desktop cache test version agnostic (#4791)
wesbillman Aug 4, 2026
e30db70
feat(projects): support multiple repositories (#4671)
thomaspblock Aug 4, 2026
b948c54
chore(release): release Buzz Desktop version 0.5.5 (#4788)
wesbillman Aug 4, 2026
4c665ae
fix(desktop): serialize tray channel actions for frontend (#4762)
kalvinnchau Aug 4, 2026
a1d78f2
feat: Buzz entity links — rich preview cards + in-app navigation for …
thomaspblock Aug 4, 2026
8faf09f
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4797)
wesbillman Aug 4, 2026
4a23051
fix: reauthenticate databricks model discovery (#4008)
kalvinnchau Aug 4, 2026
a0ed13d
chore(release): release Buzz Desktop version 0.5.5 (#4800)
wesbillman Aug 4, 2026
79c5216
Revert "chore(release): release Buzz Desktop version 0.5.5" (#4808)
wesbillman Aug 4, 2026
25a9cf1
feat: paste composer text without formatting (#4801)
kalvinnchau Aug 4, 2026
8342dfc
chore(release): release Buzz Desktop version 0.5.5 (#4809)
wesbillman Aug 4, 2026
1562cc9
feat(cli): allow generic file uploads including zip
Trevongit Aug 5, 2026
5fb4c1a
fix(cli): format generic file attachments as download links
Trevongit Aug 6, 2026
c95b14c
feat(desktop): Remote Agents section + host-agentd control plane
Trevongit Aug 8, 2026
0dba823
feat(remote-agents): seat-location.v0 proof endpoint and card surfaces
Trevongit Aug 8, 2026
9d89376
docs(remote-agents): mark P6/P7 complete on plan board
Trevongit Aug 8, 2026
ce36c0c
feat(holon): entity DNA, place-safe bodies, presence snapshot (R0–R5)
Trevongit Aug 9, 2026
b2fa594
fix(holon): address Codex P1/P2 dual-guard and presence snapshot races
Trevongit Aug 9, 2026
7d345d3
docs(operators): land multi-host agent doctrine package
Trevongit Aug 12, 2026
4fa7fa0
feat(cli): stream channel messages with `messages watch`
Trevongit Aug 12, 2026
2636d7e
fix(ci): warn on yanked spin 0.9.8 instead of failing deny
Trevongit Aug 12, 2026
ef2e713
test(cli): include messages watch in stable subcommand inventory
Trevongit Aug 12, 2026
490f288
fix(cli,ci): silence clippy dead-code and deny unmaintained pool
Trevongit Aug 12, 2026
3848742
ci(docker): scope GHCR image and buildcache to repo owner
Trevongit Aug 12, 2026
c0d2e5e
ci(docker): force lowercase GHCR image refs for forks
Trevongit Aug 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1023,7 +1023,7 @@ jobs:
git log -1 --format=%s | grep -qx smoke
echo "Host bash resolved and functional; git commit round-trip passed"
- name: Check (Tauri crate)
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --target $env:TARGET
run: cargo check --manifest-path desktop/src-tauri/Cargo.toml --workspace --all-targets --target $env:TARGET
env:
CMAKE_POLICY_VERSION_MINIMUM: "3.5"
- name: Test (Tauri crate)
Expand Down
164 changes: 164 additions & 0 deletions .github/workflows/desktop-release-cache-proof.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
name: Desktop release cache tag-scope proof

# Dispatch from a cache-proof-* tag at the same trusted-main SHA warmed by all
# four canaries. Every job restores only and requires an exact cache hit.
on:
workflow_dispatch:

permissions:
contents: read

jobs:
macos:
name: Prove macOS ${{ matrix.target }} cache visibility
if: github.repository == 'block/buzz'
runs-on: macos-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
include:
- target: aarch64-apple-darwin
features: mesh-llm
- target: x86_64-apple-darwin
features: default
steps:
- name: Require cache proof tag
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh macos)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
CACHE_TARGET: ${{ matrix.target }}
CACHE_FEATURES: ${{ matrix.features }}
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target "$CACHE_TARGET" --features "$CACHE_FEATURES" --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

linux:
name: Prove Linux cache visibility
if: github.repository == 'block/buzz'
runs-on: ubuntu-latest
container: ubuntu:24.04@sha256:4fbb8e6a8395de5a7550b33509421a2bafbc0aab6c06ba2cef9ebffbc7092d90
timeout-minutes: 15
defaults:
run:
shell: bash
steps:
- name: Require cache proof tag and install release native tools
run: |
[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }
apt-get update
apt-get install -y --no-install-recommends build-essential ca-certificates curl git libasound2-dev libayatana-appindicator3-dev libgtk-3-dev librsvg2-dev libssl-dev libwebkit2gtk-4.1-dev libxdo-dev patchelf pkg-config
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- run: git config --global --add safe.directory "$GITHUB_WORKSPACE"
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Patch proof dependency graph
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
run: echo "id=$(scripts/desktop-native-toolchain-id.sh linux)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-unknown-linux-gnu --features mesh-llm --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'

windows:
name: Prove Windows cache visibility
if: github.repository == 'block/buzz'
runs-on: windows-latest
timeout-minutes: 15
steps:
- name: Require cache proof tag
shell: bash
run: '[[ "$GITHUB_REF" == refs/tags/cache-proof-* ]] || { echo "::error::Expected cache-proof-* tag; got $GITHUB_REF"; exit 1; }'
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Patch proof dependency graph
shell: bash
run: |
cd desktop && node scripts/set-version-from-tag.mjs "0.0.0-cache-proof"
cd src-tauri && cargo update --workspace
- name: Resolve native toolchain identity
id: native_toolchain
shell: bash
run: echo "id=$(scripts/desktop-native-toolchain-id.sh windows)" >> "$GITHUB_OUTPUT"
- name: Compute exact release cache key
id: rust_cache_key
shell: bash
env:
NATIVE_TOOLCHAIN_ID: ${{ steps.native_toolchain.outputs.id }}
run: |
KEY=$(scripts/desktop-release-cache-key.py --platform "$RUNNER_OS" --target x86_64-pc-windows-msvc --features default --native-inputs "$NATIVE_TOOLCHAIN_ID")
echo "key=$KEY" >> "$GITHUB_OUTPUT"
- name: Restore exact default-branch cache from tag
id: rust_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
desktop/src-tauri/target
!desktop/src-tauri/target/**/release/bundle
key: ${{ steps.rust_cache_key.outputs.key }}
- name: Require exact cache hit
shell: bash
env:
CACHE_HIT: ${{ steps.rust_cache.outputs.cache-hit }}
CACHE_KEY: ${{ steps.rust_cache.outputs.cache-primary-key }}
EXPECTED_KEY: ${{ steps.rust_cache_key.outputs.key }}
run: '[[ "$CACHE_HIT" == true && "$CACHE_KEY" == "$EXPECTED_KEY" ]] || { echo "::error::Exact tag cache miss (hit=$CACHE_HIT restored=$CACHE_KEY expected=$EXPECTED_KEY)"; exit 1; }'
89 changes: 74 additions & 15 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
name: Docker image

# Builds and publishes the public Buzz relay images as ghcr.io/block/buzz.
# Builds and publishes the public Buzz relay images (default ghcr.io/<owner>/buzz;
# block/buzz → ghcr.io/block/buzz). Forks write cache/images to their own GHCR
# namespace so they are not denied on ghcr.io/block/* packages.
# Normal tags contain stripped binaries; matching debug-* tags contain the same
# optimized binaries with line-table debug information for native profilers.
#
Expand Down Expand Up @@ -72,11 +74,8 @@ concurrency:

permissions: {}

env:
# Single source of truth for the image name. Set GHCR_IMAGE as a repo
# variable to override (e.g., for forks that want to push to their own
# namespace without forking this file).
IMAGE_NAME: ${{ vars.GHCR_IMAGE != '' && vars.GHCR_IMAGE || 'ghcr.io/block/buzz' }}
# Image names are resolved per-job (GHCR requires fully lowercase refs;
# github.repository_owner can be mixed-case on personal forks).

jobs:
build:
Expand Down Expand Up @@ -106,6 +105,30 @@ jobs:
fetch-depth: 0
persist-credentials: false

- name: Resolve GHCR image names (lowercase)
env:
GHCR_IMAGE_VAR: ${{ vars.GHCR_IMAGE }}
GHCR_GATEWAY_VAR: ${{ vars.GHCR_PUSH_GATEWAY_IMAGE }}
run: |
set -euo pipefail
owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')"
if [ -n "${GHCR_IMAGE_VAR}" ]; then
image="${GHCR_IMAGE_VAR}"
else
image="ghcr.io/${owner}/buzz"
fi
if [ -n "${GHCR_GATEWAY_VAR}" ]; then
gateway="${GHCR_GATEWAY_VAR}"
else
gateway="ghcr.io/${owner}/buzz-push-gateway"
fi
# GHCR rejects mixed-case repository names
image="$(echo "$image" | tr '[:upper:]' '[:lower:]')"
gateway="$(echo "$gateway" | tr '[:upper:]' '[:lower:]')"
echo "IMAGE_NAME=${image}" >> "$GITHUB_ENV"
echo "GATEWAY_IMAGE=${gateway}" >> "$GITHUB_ENV"
echo "Resolved IMAGE_NAME=${image} GATEWAY_IMAGE=${gateway}"

- name: Verify tag-bound release source
if: github.ref_type == 'tag' || github.event_name == 'workflow_dispatch'
env:
Expand Down Expand Up @@ -243,6 +266,18 @@ jobs:
tag_prefix: debug-

steps:
- name: Resolve GHCR image names (lowercase)
env:
GHCR_IMAGE_VAR: ${{ vars.GHCR_IMAGE }}
GHCR_GATEWAY_VAR: ${{ vars.GHCR_PUSH_GATEWAY_IMAGE }}
run: |
set -euo pipefail
owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')"
if [ -n "${GHCR_IMAGE_VAR}" ]; then image="${GHCR_IMAGE_VAR}"; else image="ghcr.io/${owner}/buzz"; fi
if [ -n "${GHCR_GATEWAY_VAR}" ]; then gateway="${GHCR_GATEWAY_VAR}"; else gateway="ghcr.io/${owner}/buzz-push-gateway"; fi
echo "IMAGE_NAME=$(echo "$image" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
echo "GATEWAY_IMAGE=$(echo "$gateway" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"

- name: Download all per-arch digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
Expand Down Expand Up @@ -363,6 +398,17 @@ jobs:
with:
fetch-depth: 0
persist-credentials: false
- name: Resolve GHCR image names (lowercase)
env:
GHCR_IMAGE_VAR: ${{ vars.GHCR_IMAGE }}
GHCR_GATEWAY_VAR: ${{ vars.GHCR_PUSH_GATEWAY_IMAGE }}
run: |
set -euo pipefail
owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')"
if [ -n "${GHCR_IMAGE_VAR}" ]; then image="${GHCR_IMAGE_VAR}"; else image="ghcr.io/${owner}/buzz"; fi
if [ -n "${GHCR_GATEWAY_VAR}" ]; then gateway="${GHCR_GATEWAY_VAR}"; else gateway="ghcr.io/${owner}/buzz-push-gateway"; fi
echo "IMAGE_NAME=$(echo "$image" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
echo "GATEWAY_IMAGE=$(echo "$gateway" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
- name: Verify tag-bound release source
if: github.ref_type == 'tag' || github.event_name == 'workflow_dispatch'
env:
Expand All @@ -387,7 +433,7 @@ jobs:
id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
with:
images: ghcr.io/block/buzz-push-gateway
images: ${{ env.GATEWAY_IMAGE }}
labels: |
org.opencontainers.image.title=Buzz Push Gateway
org.opencontainers.image.description=Capability-gated APNs last hop for Buzz
Expand All @@ -400,9 +446,9 @@ jobs:
file: ./Dockerfile.push-gateway
platforms: ${{ matrix.platform }}
labels: ${{ steps.meta.outputs.labels }}
outputs: type=image,name=ghcr.io/block/buzz-push-gateway,push-by-digest=true,name-canonical=true,push=${{ github.event_name != 'pull_request' }}
cache-from: type=registry,ref=ghcr.io/block/buzz-push-gateway-buildcache:${{ matrix.arch }}
cache-to: ${{ (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) && format('type=registry,ref=ghcr.io/block/buzz-push-gateway-buildcache:{0},mode=max,compression=zstd', matrix.arch) || '' }}
outputs: type=image,name=${{ env.GATEWAY_IMAGE }},push-by-digest=true,name-canonical=true,push=${{ github.event_name != 'pull_request' }}
cache-from: type=registry,ref=${{ env.GATEWAY_IMAGE }}-buildcache:${{ matrix.arch }}
cache-to: ${{ (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) && format('type=registry,ref={0}-buildcache:{1},mode=max,compression=zstd', env.GATEWAY_IMAGE, matrix.arch) || '' }}
- name: Export digest
if: github.event_name != 'pull_request'
env:
Expand All @@ -429,6 +475,17 @@ jobs:
id-token: write
attestations: write
steps:
- name: Resolve GHCR image names (lowercase)
env:
GHCR_IMAGE_VAR: ${{ vars.GHCR_IMAGE }}
GHCR_GATEWAY_VAR: ${{ vars.GHCR_PUSH_GATEWAY_IMAGE }}
run: |
set -euo pipefail
owner="$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')"
if [ -n "${GHCR_IMAGE_VAR}" ]; then image="${GHCR_IMAGE_VAR}"; else image="ghcr.io/${owner}/buzz"; fi
if [ -n "${GHCR_GATEWAY_VAR}" ]; then gateway="${GHCR_GATEWAY_VAR}"; else gateway="ghcr.io/${owner}/buzz-push-gateway"; fi
echo "IMAGE_NAME=$(echo "$image" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
echo "GATEWAY_IMAGE=$(echo "$gateway" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV"
- name: Download per-arch digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
Expand All @@ -447,7 +504,7 @@ jobs:
id: meta
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
with:
images: ghcr.io/block/buzz-push-gateway
images: ${{ env.GATEWAY_IMAGE }}
tags: |
type=ref,event=branch,enable=${{ github.event_name != 'workflow_dispatch' || inputs.version == '' }}
type=sha,prefix=sha-,format=short,enable=${{ github.event_name != 'workflow_dispatch' || inputs.version == '' }}
Expand All @@ -458,28 +515,30 @@ jobs:
working-directory: /tmp/gateway-digests
env:
META_TAGS: ${{ steps.meta.outputs.tags }}
GATEWAY_IMAGE: ${{ env.GATEWAY_IMAGE }}
run: |
set -euo pipefail
tags=(); while IFS= read -r tag; do [ -n "$tag" ] && tags+=("-t" "$tag"); done <<< "$META_TAGS"
digests=(); for digest in *; do digests+=("ghcr.io/block/buzz-push-gateway@sha256:${digest}"); done
digests=(); for digest in *; do digests+=("${GATEWAY_IMAGE}@sha256:${digest}"); done
docker buildx imagetools create "${tags[@]}" "${digests[@]}"
first_tag=$(echo "$META_TAGS" | head -n1)
digest=$(docker buildx imagetools inspect "$first_tag" --format '{{json .Manifest}}' | jq -r '.digest')
echo "digest=${digest}" >> "$GITHUB_OUTPUT"
- name: Attest gateway image provenance
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-name: ghcr.io/block/buzz-push-gateway
subject-name: ${{ env.GATEWAY_IMAGE }}
subject-digest: ${{ steps.manifest.outputs.digest }}
push-to-registry: true
- name: Gateway publication summary
env:
GATEWAY_DIGEST: ${{ steps.manifest.outputs.digest }}
GATEWAY_TAGS: ${{ steps.meta.outputs.tags }}
GATEWAY_IMAGE: ${{ env.GATEWAY_IMAGE }}
run: |
set -euo pipefail
{
echo "### Published \`ghcr.io/block/buzz-push-gateway\`"
echo "### Published \`${GATEWAY_IMAGE}\`"
echo
printf "**Digest:** \`%s\`\n" "$GATEWAY_DIGEST"
echo
Expand All @@ -490,6 +549,6 @@ jobs:
echo
echo 'Verify provenance before deployment:'
echo "\`\`\`"
printf 'gh attestation verify oci://ghcr.io/block/buzz-push-gateway@%s --owner block\n' "$GATEWAY_DIGEST"
printf 'gh attestation verify oci://%s@%s --owner %s\n' "$GATEWAY_IMAGE" "$GATEWAY_DIGEST" "${{ github.repository_owner }}"
echo "\`\`\`"
} >> "$GITHUB_STEP_SUMMARY"
Loading
Loading