diff --git a/.github/workflows/ci-build.yaml b/.github/workflows/ci-build.yaml index 9086d4001ed..45411f67838 100644 --- a/.github/workflows/ci-build.yaml +++ b/.github/workflows/ci-build.yaml @@ -27,7 +27,7 @@ jobs: run: | # Copy wolfictl out of the wolfictl image and onto PATH TMP=$(mktemp -d) - docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:dd55b59445eb3a4324b6d186e15522805692504f4830ee375286ace346e5a097 -c "cp /usr/bin/wolfictl /out" + docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:4eced810def18b06511cf25737a7e99f959b1a81340858d99ed9c98776f5b11b -c "cp /usr/bin/wolfictl /out" echo "$TMP" >> $GITHUB_PATH # Assuming that we have a list of changed files such as `foo.yaml` and `bar.yaml`, this @@ -51,7 +51,7 @@ jobs: runs-on: ubuntu-16-core needs: changes container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:dd55b59445eb3a4324b6d186e15522805692504f4830ee375286ace346e5a097 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:4eced810def18b06511cf25737a7e99f959b1a81340858d99ed9c98776f5b11b options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --security-opt seccomp=unconfined --security-opt apparmor:unconfined diff --git a/.github/workflows/dag-push-production.yaml b/.github/workflows/dag-push-production.yaml index d794a83c0da..763a65bbd50 100644 --- a/.github/workflows/dag-push-production.yaml +++ b/.github/workflows/dag-push-production.yaml @@ -93,11 +93,11 @@ jobs: - run: | kubectl set image daemonset/csi-secrets-store \ -n kube-system \ - secrets-store=cgr.dev/chainguard/secrets-store-csi-driver:latest@sha256:3deee5c924791d3b4a6365f22abfb480e8de4747054fcafe4c32400af37294b2 + secrets-store=cgr.dev/chainguard/secrets-store-csi-driver:latest@sha256:0c6a89f5a96baacc66c1ed22e27239280997f6baa81579a07b208996e4a1c791 kubectl set image daemonset/csi-secrets-store-provider-gcp \ -n kube-system \ - provider=cgr.dev/chainguard/secrets-store-csi-driver-provider-gcp:latest@sha256:21419f70b9aedc080547a1d358a8529d1bc8c29c183c08d892d0b343a6519078 + provider=cgr.dev/chainguard/secrets-store-csi-driver-provider-gcp:latest@sha256:8a91cfed2786a2ab07e7ab9b3c449522c4b464afcac0f287e33e5f8e2183aa06 # Wait for DaemonSets to become ready. kubectl rollout status daemonset -n kube-system csi-secrets-store @@ -156,7 +156,7 @@ jobs: --cpu=30 --ram=100Gi \ --bucket=${BUCKET} \ --src-bucket=${SRC_BUCKET} \ - --sdk-image ghcr.io/wolfi-dev/sdk:latest@sha256:dd55b59445eb3a4324b6d186e15522805692504f4830ee375286ace346e5a097 \ + --sdk-image ghcr.io/wolfi-dev/sdk:latest@sha256:4eced810def18b06511cf25737a7e99f959b1a81340858d99ed9c98776f5b11b \ --pending-timeout=20m \ --secret-key \ --arch=arm64 diff --git a/.github/workflows/push-production.yaml b/.github/workflows/push-production.yaml index 156d3e3166b..cf16ec09e42 100644 --- a/.github/workflows/push-production.yaml +++ b/.github/workflows/push-production.yaml @@ -68,7 +68,7 @@ jobs: run: | # Copy wolfictl out of the wolfictl image and onto PATH TMP=$(mktemp -d) - docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:dd55b59445eb3a4324b6d186e15522805692504f4830ee375286ace346e5a097 -c "cp /usr/bin/wolfictl /out" + docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:4eced810def18b06511cf25737a7e99f959b1a81340858d99ed9c98776f5b11b -c "cp /usr/bin/wolfictl /out" echo "$TMP" >> $GITHUB_PATH - name: 'Build Wolfi' diff --git a/.github/workflows/wolfictl-check-update.yaml b/.github/workflows/wolfictl-check-update.yaml index 0a82a9a36e0..318ea21fdde 100644 --- a/.github/workflows/wolfictl-check-update.yaml +++ b/.github/workflows/wolfictl-check-update.yaml @@ -28,7 +28,7 @@ jobs: - name: Check id: check if: ${{ steps.files.outputs.all_changed_files != '' }} - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7e693b6957ee6e3d66a9446dc2cd604dbf86f31fa4d8b9200fd8c7a742c5928c + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:fce9af18bb78d9a6e28bc7b78f29503923532a0eff114334d6b0e1b8d5a8e5f0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: diff --git a/.github/workflows/wolfictl-lint.yaml b/.github/workflows/wolfictl-lint.yaml index bdcfa07d768..222dd4781a5 100644 --- a/.github/workflows/wolfictl-lint.yaml +++ b/.github/workflows/wolfictl-lint.yaml @@ -19,13 +19,13 @@ jobs: - uses: actions/checkout@v3 - name: Lint id: lint - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7e693b6957ee6e3d66a9446dc2cd604dbf86f31fa4d8b9200fd8c7a742c5928c + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:fce9af18bb78d9a6e28bc7b78f29503923532a0eff114334d6b0e1b8d5a8e5f0 with: entrypoint: wolfictl args: lint --skip-rule no-makefile-entry-for-package - name: Enforce YAML formatting id: lint-yaml - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7e693b6957ee6e3d66a9446dc2cd604dbf86f31fa4d8b9200fd8c7a742c5928c + uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:fce9af18bb78d9a6e28bc7b78f29503923532a0eff114334d6b0e1b8d5a8e5f0 with: entrypoint: wolfictl args: lint yam diff --git a/.github/workflows/wolfictl-update-gh.yaml b/.github/workflows/wolfictl-update-gh.yaml index 329f1277f20..30d7fa210f1 100644 --- a/.github/workflows/wolfictl-update-gh.yaml +++ b/.github/workflows/wolfictl-update-gh.yaml @@ -23,7 +23,7 @@ jobs: steps: - uses: actions/checkout@v3 - - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7e693b6957ee6e3d66a9446dc2cd604dbf86f31fa4d8b9200fd8c7a742c5928c + - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:fce9af18bb78d9a6e28bc7b78f29503923532a0eff114334d6b0e1b8d5a8e5f0 with: entrypoint: wolfictl args: update https://github.com/${{github.repository}} --release-monitoring-query=false --github-labels request-version-update --github-labels "automated pr" diff --git a/.github/workflows/wolfictl-update-rm.yaml b/.github/workflows/wolfictl-update-rm.yaml index 4fffe3919a6..28eed7e5e07 100644 --- a/.github/workflows/wolfictl-update-rm.yaml +++ b/.github/workflows/wolfictl-update-rm.yaml @@ -23,7 +23,7 @@ jobs: steps: - uses: actions/checkout@v3 - - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:7e693b6957ee6e3d66a9446dc2cd604dbf86f31fa4d8b9200fd8c7a742c5928c + - uses: docker://ghcr.io/wolfi-dev/wolfictl:latest@sha256:fce9af18bb78d9a6e28bc7b78f29503923532a0eff114334d6b0e1b8d5a8e5f0 with: entrypoint: wolfictl args: update https://github.com/${{github.repository}} --github-release-query=false --github-labels request-version-update --github-labels "automated pr"