Files
qdrant/.github/workflows/dev-docker-image-build.yml
Tim Visée 9acece1e2c Set GitHub workflow permissions explicitly (#9432)
* Potential fix for code scanning alert no. 7: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 9: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 10: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 19: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 20: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Set permissions in GitHub workflow jobs

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-06-11 16:02:12 +02:00

50 lines
1.6 KiB
YAML

name: Build and push a branch image to ghcr
on:
workflow_dispatch:
push:
branches:
- dev
- master
repository_dispatch:
types: [benchmark-trigger-image-build]
permissions:
contents: read
jobs:
branch-build-and-push:
if: ${{ !github.event.client_payload.triggered }}
runs-on: [self-hosted, linux, x64]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
ref: ${{ github.ref_name }}
- uses: ./.github/actions/branch-build-and-push
with:
ghcr-password: ${{ secrets.GITHUB_TOKEN }}
dockerhub-password: ${{ secrets.DOCKERHUB_TOKEN }}
push-to-ghcr: true
# Only push 'dev' and 'master' branch to Docker Hub
push-to-dockerhub: ${{ github.ref_name == 'dev' || github.ref_name == 'master' }}
# Enable `staging` feature for all branches except master (tags are excluded by ref_type check)
staging-build: ${{ github.ref_type == 'branch' && github.ref_name != 'master' }}
triggered-branch-build-and-push:
if: ${{ github.event.client_payload.triggered }}
runs-on: [self-hosted, linux, x64]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
ref: ${{ github.event.client_payload.version }}
- uses: ./.github/actions/branch-build-and-push
with:
ghcr-password: ${{ secrets.GITHUB_TOKEN }}
push-to-ghcr: true