Skip to content

Merge pull request #309 from smallstep/max/bump-dependencies #25

Merge pull request #309 from smallstep/max/bump-dependencies

Merge pull request #309 from smallstep/max/bump-dependencies #25

Triggered via push November 21, 2024 00:59
Status Success
Total duration 11m 54s
Artifacts 4

release.yml

on: push
Matrix: ci / ci / codeql / CodeQL Analyze
ci  /  ...  /  set-go-matrix
0s
ci / ci / build / set-go-matrix
ci  /  ...  /  set-go-matrix
0s
ci / ci / test / set-go-matrix
ci  /  ...  /  actionlint
7s
ci / ci / actionlint
ci  /  ...  /  lint
1m 4s
ci / ci / lint / lint
ci  /  ...  /  govulncheck
19s
ci / ci / govulncheck / govulncheck
Matrix: ci / ci / build / build
Matrix: ci / ci / test / test
Create Release
2s
Create Release
goreleaser  /  Upload Assets To Github w/ goreleaser
1m 12s
goreleaser / Upload Assets To Github w/ goreleaser
Build & Upload Autocert Init Docker Images  /  Build & Upload Docker Images
46s
Build & Upload Autocert Init Docker Images / Build & Upload Docker Images
Build & Upload Autocert Renewer Images  /  Build & Upload Docker Images
51s
Build & Upload Autocert Renewer Images / Build & Upload Docker Images
Build & Upload Autocert Bootstrapper Images  /  Build & Upload Docker Images
46s
Build & Upload Autocert Bootstrapper Images / Build & Upload Docker Images
Build & Upload Autocert Bootstrapper Images  /  Build & Upload Docker Images
9m 34s
Build & Upload Autocert Bootstrapper Images / Build & Upload Docker Images
Fit to window
Zoom out
Zoom in

Annotations

4 warnings
Sensitive data should not be used in the ARG or ENV commands: bootstrapper/Dockerfile#L5
SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
Sensitive data should not be used in the ARG or ENV commands: renewer/Dockerfile#L5
SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
goreleaser / Upload Assets To Github w/ goreleaser
You are using 'latest' as default version. Will lock to '~> v2'.
JSON arguments recommended for ENTRYPOINT/CMD to prevent unintended behavior related to OS signals: controller/Dockerfile#L17
JSONArgsRecommended: JSON arguments recommended for ENTRYPOINT to prevent unintended behavior related to OS signals More info: https://docs.docker.com/go/dockerfile/rule/json-args-recommended/

Artifacts

Produced during runtime
Name Size
smallstep~autocert~6D5MCU.dockerbuild
56.3 KB
smallstep~autocert~JC3J9H.dockerbuild
39 KB
smallstep~autocert~TJ1R01.dockerbuild
65.2 KB
smallstep~autocert~YHDJTT.dockerbuild
82 KB