diff --git a/.github/workflows/.ci-build.yml b/.github/workflows/.ci-build.yml index 9fe87eab..9af05c78 100644 --- a/.github/workflows/.ci-build.yml +++ b/.github/workflows/.ci-build.yml @@ -74,7 +74,7 @@ jobs: timeout-minutes: 600 # default is 360 container: - image: ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + image: ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 options: | --cap-add NET_ADMIN --cap-add SYS_ADMIN --device /dev/fuse --security-opt seccomp=unconfined --security-opt apparmor:unconfined diff --git a/advisories-validate/action.yaml b/advisories-validate/action.yaml index 0efed05a..f5b8d22e 100644 --- a/advisories-validate/action.yaml +++ b/advisories-validate/action.yaml @@ -37,7 +37,7 @@ inputs: runs: using: 'docker' - image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 entrypoint: wolfictl args: - adv diff --git a/build-and-publish-osv/action.yaml b/build-and-publish-osv/action.yaml index 3912188d..1f306f35 100644 --- a/build-and-publish-osv/action.yaml +++ b/build-and-publish-osv/action.yaml @@ -66,7 +66,7 @@ runs: shell: bash - name: Build the security database - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: advisory osv -o osv ${{ inputs.wolfictl_args }} diff --git a/build-and-publish-secdb/action.yaml b/build-and-publish-secdb/action.yaml index edb907c6..543a13ac 100644 --- a/build-and-publish-secdb/action.yaml +++ b/build-and-publish-secdb/action.yaml @@ -61,7 +61,7 @@ runs: shell: bash - name: Build the security database - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: ${{ inputs.wolfictl_args }} diff --git a/build-and-publish-yaml/action.yaml b/build-and-publish-yaml/action.yaml index 66850360..2a8754be 100644 --- a/build-and-publish-yaml/action.yaml +++ b/build-and-publish-yaml/action.yaml @@ -56,7 +56,7 @@ runs: shell: bash - name: Build the security database - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: ${{ inputs.wolfictl_args }} diff --git a/install-wolfictl/action.yaml b/install-wolfictl/action.yaml index 4005552f..28ba83e5 100644 --- a/install-wolfictl/action.yaml +++ b/install-wolfictl/action.yaml @@ -10,6 +10,6 @@ runs: run: | # Copy wolfictl out of the wolfictl image and onto PATH TMP=$(mktemp -d) - docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 -c "cp /usr/bin/wolfictl /out" + docker run --rm -i -v $TMP:/out --entrypoint /bin/sh ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 -c "cp /usr/bin/wolfictl /out" echo "$TMP" >> $GITHUB_PATH shell: bash diff --git a/wolfictl-check-updates/action.yaml b/wolfictl-check-updates/action.yaml index 72f77dc8..a1f3469f 100644 --- a/wolfictl-check-updates/action.yaml +++ b/wolfictl-check-updates/action.yaml @@ -19,7 +19,7 @@ runs: using: "composite" steps: - name: wolfictl-check-updates - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: check update ${{ inputs.changed_files }} diff --git a/wolfictl-lint/action.yaml b/wolfictl-lint/action.yaml index b2bf9c8c..f7ca77f8 100644 --- a/wolfictl-lint/action.yaml +++ b/wolfictl-lint/action.yaml @@ -26,7 +26,7 @@ runs: - name: Lint if: ${{ inputs.run_wolfictl_lint == 'true' }} id: lint - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: --log-level info lint --skip-rule no-makefile-entry-for-package ${{ inputs.args }} @@ -34,7 +34,7 @@ runs: - name: Enforce YAML formatting if: ${{ inputs.run_wolfictl_lint_yam == 'true' }} id: lint-yaml - uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + uses: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 with: entrypoint: wolfictl args: lint yam ${{ inputs.args }} diff --git a/wolfictl-update-gh/action.yaml b/wolfictl-update-gh/action.yaml index 6ba3cab1..ad777bfc 100644 --- a/wolfictl-update-gh/action.yaml +++ b/wolfictl-update-gh/action.yaml @@ -27,7 +27,7 @@ inputs: runs: using: 'docker' - image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 entrypoint: wolfictl args: - update diff --git a/wolfictl-update-rm/action.yaml b/wolfictl-update-rm/action.yaml index 52b2e611..b08c6d55 100644 --- a/wolfictl-update-rm/action.yaml +++ b/wolfictl-update-rm/action.yaml @@ -32,7 +32,7 @@ inputs: runs: using: 'docker' - image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:bfe574a465dd54bdec763eac1180abd64beadb426638354a6b34c9948c7cde62 + image: docker://ghcr.io/wolfi-dev/sdk:latest@sha256:79b07e788dd1c12dcabc8c10df6b8921fb7e5a391d5bc7bf4a7844e3cdcf27d5 entrypoint: wolfictl args: - update