What changed, and why it matters
This commit adds a new GitHub Actions workflow file that automatically builds and publishes a Docker builder image when the main branch changes. It is a routine CI/CD configuration change with no apparent security defect.
No security action required. As a general hygiene measure, consider pinning actions to full commit SHAs and verifying that the Dockerfile referenced by this workflow does not introduce supply-chain risks.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff introduces .github/workflows/builder-image-build.yml, which checks out the repository, logs into GHCR using the automatically provided GITHUB_TOKEN, builds a Docker image for linux/amd64, pushes it with SHA and latest tags, and generates an artifact attestation. The workflow follows standard GitHub Actions practices: least-privilege job permissions (contents: read, packages: write, id-token: write), pinned major versions of official actions, and build-provenance attestation. No secrets are exposed, no untrusted inputs are executed, and no code is modified.
Changed components
.github/workflows/builder-image-build.ymlInspect captured patch +65 / −0
diff --git a/.github/workflows/builder-image-build.yml b/.github/workflows/builder-image-build.yml
new file mode 100644
index 0000000..89ddbc5
--- /dev/null
+++ b/.github/workflows/builder-image-build.yml
@@ -0,0 +1,65 @@
+name: Build Builder Docker Image
+
+on:
+ push:
+ branches:
+ - main
+ paths:
+ - 'Dockerfile'
+ - '.github/workflows/docker.yml'
+ workflow_dispatch:
+
+env:
+ REGISTRY: ghcr.io
+ IMAGE_NAME: ${{ github.repository }}-builder
+
+jobs:
+ build-and-push:
+ name: Build and Push Docker Image
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+ packages: write
+ id-token: write
+
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Set up Docker Buildx
+ uses: docker/setup-buildx-action@v3
+
+ - name: Log in to GitHub Container Registry
+ uses: docker/login-action@v3
+ with:
+ registry: ${{ env.REGISTRY }}
+ username: ${{ github.actor }}
+ password: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Extract metadata for Docker
+ id: meta
+ uses: docker/metadata-action@v5
+ with:
+ images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
+ tags: |
+ type=sha,prefix=
+ type=raw,value=latest
+
+ - name: Build and push Docker image
+ id: build
+ uses: docker/build-push-action@v5
+ with:
+ context: .
+ platforms: linux/amd64
+ push: true
+ tags: ${{ steps.meta.outputs.tags }}
+ labels: ${{ steps.meta.outputs.labels }}
+ cache-from: type=gha
+ cache-to: type=gha,mode=max
+
+ - name: Generate artifact attestation
+ uses: actions/attest-build-provenance@v2
+ with:
+ subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
+ subject-digest: ${{ steps.build.outputs.digest }}
+ push-to-registry: true
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.