Skip to content

ci: publish downstream image to GHCR - #3

Merged
constbogdan merged 1 commit into
downstream-mainfrom
chore/downstream-image-publication
Sep 23, 2026
Merged

constbogdan merged 1 commit into
downstream-mainfrom
chore/downstream-image-publication

Conversation

@constbogdan

Copy link
Copy Markdown
Owner

Summary

  • add a downstream-owned GHCR publisher for protected downstream-main
  • publish immutable full-SHA and rolling downstream tags
  • build linux/amd64 with the existing Seerr Dockerfile
  • report the published digest and run identity in the workflow summary
  • update the workflow inventory and downstream maintenance documentation

Security boundary

Publication requires the exact constbogdan/seerr repository and
refs/heads/downstream-main ref. The workflow has only contents: read and
packages: write permissions.

It does not publish to Docker Hub, run for PRs/tags/manual dispatches, create
GitHub Releases, or modify inherited upstream workflows.

Validation

  • all workflow YAML parses
  • workflow inventory matches
  • Prettier passes
  • all inherited workflow files remain identical to upstream/develop
  • git diff --check passes

@constbogdan constbogdan changed the title feat: downstream-image-publication ci: publish downstream image to GHCR Sep 23, 2026
@constbogdan
constbogdan merged commit f74657a into downstream-main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant