diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 0d5d9e2..084623f 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -6,6 +6,10 @@ on: - "main" workflow_dispatch: +permissions: + contents: read + packages: write + env: REGISTRY: ghcr.io IMAGE_REPO: ${{ github.repository }} @@ -19,29 +23,22 @@ jobs: with: submodules: 'recursive' - name: Set up QEMU - uses: docker/setup-qemu-action@v1 + uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v1 - - name: Cache Docker layers - uses: actions/cache@v4 - with: - path: /tmp/.buildx-cache - key: ${{ runner.os }}-buildx-${{ github.sha }} - restore-keys: | - ${{ runner.os }}-buildx- - - name: Login to Docker Hub + uses: docker/setup-buildx-action@v3 + - name: Login to GitHub Container Registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ github.repository_owner }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and push - uses: docker/build-push-action@v2 + uses: docker/build-push-action@v6 with: context: . file: ./Dockerfile push: true tags: ${{ env.REGISTRY }}/${{ env.IMAGE_REPO }}:latest - platforms: linux/arm64/v8 - cache-from: type=local,src=/tmp/.buildx-cache - cache-to: type=local,dest=/tmp/.buildx-cache + platforms: linux/arm64 + cache-from: type=gha + cache-to: type=gha,mode=max