Files
release-factory/.github/workflows/build-opencode-workstation.yml
T
okxlin 2ffcf17dfd fix(release): repair image builds, update DSH, and stop ci tag publication (#90)
Repair Selkies file smoke checks and DSH 0.2 telemetry compatibility; update pinned components and vulnerable bundled dependencies. Publish tested images by verified digest before advancing release tags, without ci tags.

Supersedes #88. All final-head native build, runtime and security checks passed.
2026-09-30 17:24:37 +08:00

51 lines
1.6 KiB
YAML

name: Build OpenCode Workstation Image
on:
workflow_dispatch:
inputs:
image_tag:
description: "Published image tag; leave empty for the default release tag"
default: ""
type: string
platforms:
description: "Comma-separated target platforms"
default: linux/amd64,linux/arm64
type: string
push_latest:
description: "Also publish latest"
default: false
type: boolean
schedule:
- cron: "11 4 * * 0"
pull_request:
paths:
- 'opencode-workstation-builder/**'
- '.github/workflows/build-opencode-workstation.yml'
- '.github/workflows/release-workstations.yml'
- 'scripts/smoke-opencode-workstation.py'
- 'scripts/trivy-image-gate.sh'
- 'scripts/evaluate-trivy-policy.py'
- 'scripts/test-evaluate-trivy-policy.py'
- 'scripts/publish-tested-image.py'
- 'scripts/registry_image.py'
- 'scripts/test-registry-image.py'
- 'scripts/test-publish-tested-image.py'
permissions:
contents: read
packages: write
concurrency:
group: build-opencode-workstation-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
release:
uses: ./.github/workflows/release-workstations.yml
with:
variant: opencode
image_tag: ${{ inputs.image_tag || '' }}
platforms: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
push_latest: ${{ github.event_name == 'schedule' || inputs.push_latest == true }}
publish: ${{ github.event_name != 'pull_request' && github.ref == 'refs/heads/main' }}