mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 4.0.0 to 4.2.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/docker/setup-qemu-action/releases">docker/setup-qemu-action's releases</a>.</em></p> <blockquote> <h2>v4.2.0</h2> <ul> <li>Preserve names in esbuild bundle by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/311">docker/setup-qemu-action#311</a></li> <li>Bump <code>@actions/core</code> from 3.0.0 to 3.0.1 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/295">docker/setup-qemu-action#295</a></li> <li>Bump <code>@docker/actions-toolkit</code> from 0.91.0 to 0.92.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/315">docker/setup-qemu-action#315</a></li> <li>Bump <code>@sigstore/core</code> from 3.1.0 to 3.2.1 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/312">docker/setup-qemu-action#312</a></li> <li>Bump js-yaml from 4.1.1 to 4.2.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/310">docker/setup-qemu-action#310</a></li> <li>Bump tmp from 0.2.6 to 0.2.7 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/304">docker/setup-qemu-action#304</a></li> <li>Bump undici from 6.26.0 to 6.27.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/308">docker/setup-qemu-action#308</a></li> <li>Bump vite from 7.3.2 to 7.3.6 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/307">docker/setup-qemu-action#307</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/docker/setup-qemu-action/compare/v4.1.0...v4.2.0">https://github.com/docker/setup-qemu-action/compare/v4.1.0...v4.2.0</a></p> <h2>v4.1.0</h2> <ul> <li>Add <code>reset</code> input to uninstall current emulators by <a href="https://github.com/crazy-max"><code>@crazy-max</code></a> in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/21">docker/setup-qemu-action#21</a></li> <li>Bump <code>@docker/actions-toolkit</code> from 0.77.0 to 0.91.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/250">docker/setup-qemu-action#250</a> <a href="https://redirect.github.com/docker/setup-qemu-action/pull/247">docker/setup-qemu-action#247</a></li> <li>Bump brace-expansion from 1.1.12 to 1.1.15 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/265">docker/setup-qemu-action#265</a></li> <li>Bump fast-xml-builder from 1.0.0 to 1.2.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/286">docker/setup-qemu-action#286</a></li> <li>Bump fast-xml-parser from 5.4.2 to 5.8.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/255">docker/setup-qemu-action#255</a></li> <li>Bump flatted from 3.3.3 to 3.4.2 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/257">docker/setup-qemu-action#257</a></li> <li>Bump glob from 10.3.15 to 10.5.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/254">docker/setup-qemu-action#254</a></li> <li>Bump handlebars from 4.7.8 to 4.7.9 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/262">docker/setup-qemu-action#262</a></li> <li>Bump lodash from 4.17.23 to 4.18.1 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/273">docker/setup-qemu-action#273</a></li> <li>Bump postcss from 8.5.6 to 8.5.10 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/285">docker/setup-qemu-action#285</a></li> <li>Bump tar from 6.2.1 to 7.5.15 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/287">docker/setup-qemu-action#287</a></li> <li>Bump tmp from 0.2.5 to 0.2.6 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/291">docker/setup-qemu-action#291</a></li> <li>Bump undici from 6.23.0 to 6.26.0 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/251">docker/setup-qemu-action#251</a></li> <li>Bump vite from 7.3.1 to 7.3.2 in <a href="https://redirect.github.com/docker/setup-qemu-action/pull/271">docker/setup-qemu-action#271</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/docker/setup-qemu-action/compare/v4.0.0...v4.1.0">https://github.com/docker/setup-qemu-action/compare/v4.0.0...v4.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/docker/setup-qemu-action/commit/96fe6ef7f33517b61c61be40b68a1882f3264fb8"><code>96fe6ef</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-qemu-action/issues/315">#315</a> from docker/dependabot/npm_and_yarn/docker/actions-to...</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/31f08d3fc9186dbe4b4550696f2e32e9aa7f9465"><code>31f08d3</code></a> [dependabot skip] chore: update generated content</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/4e7017a474d2cf3912bb0437f7fafec6d5fb6c52"><code>4e7017a</code></a> build(deps): bump <code>@docker/actions-toolkit</code> from 0.91.0 to 0.92.0</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/0eca235293ca1939b58c082f69bdc981ccce8c94"><code>0eca235</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-qemu-action/issues/314">#314</a> from crazy-max/fix-yarn-preapprove-actions-toolkit</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/ea66a4130b037e7961e14a0e5b155836e797cced"><code>ea66a41</code></a> chore: allow actions-toolkit to bypass yarn age gate</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/451542b03ae7946b7082a398b11c8c315a0e4e80"><code>451542b</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-qemu-action/issues/308">#308</a> from docker/dependabot/npm_and_yarn/undici-6.27.0</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/532ae0057542ec2102e2d19e9feccf85f1f69013"><code>532ae00</code></a> [dependabot skip] chore: update generated content</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/b6f5af659afad3f9931b782668dee4595ae7e841"><code>b6f5af6</code></a> build(deps): bump undici from 6.26.0 to 6.27.0</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/cf96b86294b57480ac6d330bd177fca87eac95bc"><code>cf96b86</code></a> Merge pull request <a href="https://redirect.github.com/docker/setup-qemu-action/issues/304">#304</a> from docker/dependabot/npm_and_yarn/tmp-0.2.7</li> <li><a href="https://github.com/docker/setup-qemu-action/commit/f0ba643f78dc96bc931fb83e5dadc39628e10047"><code>f0ba643</code></a> [dependabot skip] chore: update generated content</li> <li>Additional commits viewable in <a href="https://github.com/docker/setup-qemu-action/compare/ce360397dd3f832beb865e1373c09c0e9f86d70a...96fe6ef7f33517b61c61be40b68a1882f3264fb8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Anthony Stirling <77850077+Frooodle@users.noreply.github.com>
244 lines
10 KiB
YAML
244 lines
10 KiB
YAML
name: Build Docker images (PR test)
|
||
|
||
# Reusable workflow called from build.yml on PRs to verify the three
|
||
# embedded Dockerfiles (default, ultra-lite, fat) still build cleanly,
|
||
# optionally against a freshly-built base image when the PR touches the
|
||
# base Dockerfile.
|
||
on:
|
||
workflow_call:
|
||
inputs:
|
||
docker-base-changed:
|
||
description: "Whether the docker base image changed (forwarded from files-changed)."
|
||
required: false
|
||
type: string
|
||
default: "false"
|
||
dockerfiles-changed:
|
||
description: "Whether any Dockerfile changed (forwarded from files-changed). Gates the slow arm64 build leg."
|
||
required: false
|
||
type: string
|
||
default: "false"
|
||
|
||
permissions:
|
||
contents: read
|
||
|
||
jobs:
|
||
# TODO: extract a pre-matrix `prepare` job that runs once and produces
|
||
# shared artifacts for the three matrix entries below to consume:
|
||
# 1. `task backend:build` — currently runs 3× in parallel with
|
||
# identical env (DISABLE_ADDITIONAL_FEATURES=true,
|
||
# STIRLING_PDF_DESKTOP_UI=false). Build once, upload the JAR as an
|
||
# artifact, matrix entries download.
|
||
# 2. The base-image `docker build` (gated on docker-base-changed) —
|
||
# currently runs 3× in parallel against the same Dockerfile and
|
||
# context. Build once, `docker save` to an artifact, matrix entries
|
||
# `docker load` before the embedded build.
|
||
# Saves ~2 full backend builds + 2 base-image builds per PR that touches
|
||
# docker. May also be reusable from backend-build.yml's jdk-25 +
|
||
# spring-security=true matrix entry if `task backend:build` and
|
||
# `task backend:build:ci` produce equivalent JARs (verify before wiring).
|
||
test-build-docker-images:
|
||
runs-on: ubuntu-latest
|
||
strategy:
|
||
fail-fast: false
|
||
matrix:
|
||
include:
|
||
- docker-rev: docker/embedded/Dockerfile
|
||
artifact-suffix: Dockerfile
|
||
cache-scope: stirling-pdf-latest
|
||
- docker-rev: docker/embedded/Dockerfile.ultra-lite
|
||
artifact-suffix: Dockerfile.ultra-lite
|
||
cache-scope: stirling-pdf-ultra-lite
|
||
- docker-rev: docker/embedded/Dockerfile.fat
|
||
artifact-suffix: Dockerfile.fat
|
||
cache-scope: stirling-pdf-fat
|
||
steps:
|
||
- name: Harden Runner
|
||
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
|
||
with:
|
||
egress-policy: audit
|
||
|
||
- name: Checkout Repository
|
||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||
|
||
- name: Login to GitHub Container Registry
|
||
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||
with:
|
||
registry: ghcr.io
|
||
username: ${{ github.actor }}
|
||
password: ${{ github.token }}
|
||
|
||
- name: Convert repository owner to lowercase
|
||
id: repoowner
|
||
run: echo "lowercase=$(echo ${{ github.repository_owner }} | awk '{print tolower($0)}')" >> $GITHUB_OUTPUT
|
||
|
||
- name: Free disk space on runner
|
||
run: |
|
||
echo "Disk space before cleanup:" && df -h
|
||
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android /usr/local/share/boost
|
||
docker system prune -af || true
|
||
echo "Disk space after cleanup:" && df -h
|
||
|
||
- name: Set up JDK 25
|
||
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
||
with:
|
||
java-version: "25"
|
||
distribution: "temurin"
|
||
|
||
- name: Cache Gradle User Home
|
||
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||
with:
|
||
path: |
|
||
~/.gradle/caches
|
||
~/.gradle/wrapper
|
||
key: gradle-${{ runner.os }}-${{ runner.arch }}-jdk-25-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
||
restore-keys: |
|
||
gradle-${{ runner.os }}-${{ runner.arch }}-jdk-25-
|
||
gradle-${{ runner.os }}-${{ runner.arch }}-
|
||
|
||
- name: Install Task
|
||
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
||
- name: Build application
|
||
run: task backend:build
|
||
env:
|
||
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
||
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||
DISABLE_ADDITIONAL_FEATURES: true
|
||
STIRLING_PDF_DESKTOP_UI: false
|
||
|
||
- name: Set up QEMU
|
||
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
|
||
|
||
- name: Set up Docker Buildx
|
||
id: buildx
|
||
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
|
||
|
||
- name: Build base image locally (PR base change only)
|
||
if: github.event_name == 'pull_request' && inputs.docker-base-changed == 'true'
|
||
run: |
|
||
docker build -t stirling-pdf-base:pr-test -f docker/base/Dockerfile docker/base
|
||
|
||
- name: Set base image and platform for this build
|
||
id: build-params
|
||
# Pass workflow inputs through env vars rather than expanding `${{ }}`
|
||
# directly into the shell — defense-in-depth against template injection
|
||
# if any upstream provider of these values ever becomes less trusted.
|
||
# GITHUB_EVENT_NAME is already provided by the runner.
|
||
env:
|
||
DOCKER_BASE_CHANGED: ${{ inputs.docker-base-changed }}
|
||
DOCKERFILES_CHANGED: ${{ inputs.dockerfiles-changed }}
|
||
run: |
|
||
if [ "$GITHUB_EVENT_NAME" = "pull_request" ] && [ "$DOCKER_BASE_CHANGED" = "true" ]; then
|
||
# Base Dockerfile changed: build against the locally-built base,
|
||
# which only exists for amd64.
|
||
echo "base_image=stirling-pdf-base:pr-test" >> "$GITHUB_OUTPUT"
|
||
echo "platforms=linux/amd64" >> "$GITHUB_OUTPUT"
|
||
elif [ "$DOCKERFILES_CHANGED" = "true" ]; then
|
||
# A Dockerfile changed: also verify the arm64 build (slow QEMU leg).
|
||
echo "base_image=stirlingtools/stirling-pdf-base:latest" >> "$GITHUB_OUTPUT"
|
||
echo "platforms=linux/amd64,linux/arm64/v8" >> "$GITHUB_OUTPUT"
|
||
else
|
||
# No Dockerfile change: amd64 only. arm64 is exercised on the base
|
||
# image publish and on release, not on every code PR.
|
||
echo "base_image=stirlingtools/stirling-pdf-base:latest" >> "$GITHUB_OUTPUT"
|
||
echo "platforms=linux/amd64" >> "$GITHUB_OUTPUT"
|
||
fi
|
||
|
||
# Base-changed PRs build the embedded image with the local docker driver
|
||
# so the locally-built stirling-pdf-base:pr-test (in the daemon image
|
||
# store) resolves. A buildx container builder cannot see it and would try
|
||
# to pull it from a registry, which fails. Single-platform, no gha cache.
|
||
- name: Build ${{ matrix.docker-rev }} against local base (PR base change)
|
||
if: github.event_name == 'pull_request' && inputs.docker-base-changed == 'true'
|
||
run: |
|
||
DOCKER_BUILDKIT=1 docker build \
|
||
--build-arg BASE_IMAGE=${{ steps.build-params.outputs.base_image }} \
|
||
--file ./${{ matrix.docker-rev }} \
|
||
--tag stirling-pdf-embedded:pr-test \
|
||
.
|
||
|
||
# PRs that did NOT change the base use the buildx container builder
|
||
# (multi-platform + gha cache) against the published base image.
|
||
- name: Build ${{ matrix.docker-rev }}
|
||
if: inputs.docker-base-changed != 'true'
|
||
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
|
||
with:
|
||
builder: ${{ steps.buildx.outputs.name }}
|
||
context: .
|
||
file: ./${{ matrix.docker-rev }}
|
||
push: false
|
||
cache-from: type=gha,scope=${{ matrix.cache-scope }}
|
||
cache-to: type=gha,mode=max,scope=${{ matrix.cache-scope }}
|
||
platforms: ${{ steps.build-params.outputs.platforms }}
|
||
build-args: |
|
||
BASE_IMAGE=${{ steps.build-params.outputs.base_image }}
|
||
provenance: true
|
||
sbom: true
|
||
|
||
- name: Upload Reports
|
||
if: always()
|
||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||
with:
|
||
name: reports-docker-${{ matrix.artifact-suffix }}
|
||
path: |
|
||
build/reports/tests/
|
||
build/test-results/
|
||
build/reports/problems/
|
||
retention-days: 3
|
||
if-no-files-found: warn
|
||
|
||
test-build-unoserver-image:
|
||
runs-on: ubuntu-latest
|
||
steps:
|
||
- name: Harden Runner
|
||
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
|
||
with:
|
||
egress-policy: audit
|
||
|
||
- name: Checkout Repository
|
||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||
|
||
- name: Set up QEMU
|
||
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
|
||
|
||
- name: Set up Docker Buildx
|
||
id: buildx
|
||
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
|
||
|
||
- name: Build docker/unoserver/Dockerfile
|
||
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
|
||
with:
|
||
builder: ${{ steps.buildx.outputs.name }}
|
||
context: .
|
||
file: ./docker/unoserver/Dockerfile
|
||
push: false
|
||
load: true
|
||
cache-from: type=gha,scope=stirling-unoserver
|
||
cache-to: type=gha,mode=max,scope=stirling-unoserver
|
||
platforms: linux/amd64
|
||
tags: stirling-unoserver:pr-test
|
||
provenance: false
|
||
sbom: false
|
||
|
||
- name: Smoke test the built image
|
||
run: |
|
||
set -eu
|
||
docker run -d --name unoserver-smoke \
|
||
-e UNOSERVER_RECYCLE_INTERVAL_SECONDS=0 \
|
||
stirling-unoserver:pr-test
|
||
deadline=$((SECONDS + 60))
|
||
while [ $SECONDS -lt $deadline ]; do
|
||
status=$(docker inspect -f '{{.State.Health.Status}}' unoserver-smoke 2>/dev/null || echo "starting")
|
||
if [ "$status" = "healthy" ]; then
|
||
echo "unoserver became healthy"
|
||
docker logs unoserver-smoke | tail -30
|
||
docker rm -f unoserver-smoke
|
||
exit 0
|
||
fi
|
||
sleep 3
|
||
done
|
||
echo "unoserver did not become healthy in time"
|
||
docker logs unoserver-smoke || true
|
||
docker rm -f unoserver-smoke || true
|
||
exit 1
|