From d506a814347c5fc38c8bcf7357f418e0cf64140a Mon Sep 17 00:00:00 2001 From: Vishwajit Dusunge Date: Sun, 27 Sep 2026 01:06:16 +0530 Subject: [PATCH 1/3] Remove the TODO from the slsa-provenance.md --- content/manuals/build/metadata/attestations/slsa-provenance.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/content/manuals/build/metadata/attestations/slsa-provenance.md b/content/manuals/build/metadata/attestations/slsa-provenance.md index 54e00c78933a..19d62ed23f1e 100644 --- a/content/manuals/build/metadata/attestations/slsa-provenance.md +++ b/content/manuals/build/metadata/attestations/slsa-provenance.md @@ -202,8 +202,6 @@ RUN apt-get update ## Provenance attestation example - - The following example shows what a JSON representation of a provenance attestation with `mode=max` looks like: From 5e83b4e2d25db560e06d238b98de3e98868d355e Mon Sep 17 00:00:00 2001 From: Vishwajit Dusunge Date: Sun, 27 Sep 2026 01:13:16 +0530 Subject: [PATCH 2/3] Removed the redundant TODO from ci.md --- content/manuals/build-cloud/ci.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/content/manuals/build-cloud/ci.md b/content/manuals/build-cloud/ci.md index 42227f6177f2..c62f4f50f905 100644 --- a/content/manuals/build-cloud/ci.md +++ b/content/manuals/build-cloud/ci.md @@ -94,8 +94,6 @@ If you are not an organization administrator: ### GitHub Actions - - ```yaml name: ci From f2f36d7905188256cd6c1ad8b41e544ca0558ca7 Mon Sep 17 00:00:00 2001 From: Vishwajit Dusunge Date: Sun, 27 Sep 2026 18:31:12 +0530 Subject: [PATCH 3/3] Fix Docker Build Cloud CI examples --- content/manuals/build-cloud/ci.md | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/content/manuals/build-cloud/ci.md b/content/manuals/build-cloud/ci.md index c62f4f50f905..d8788aa1f92c 100644 --- a/content/manuals/build-cloud/ci.md +++ b/content/manuals/build-cloud/ci.md @@ -101,9 +101,13 @@ on: push: branches: - "main" + pull_request: + branches: + - "main" jobs: docker: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: - name: Login to Docker Hub @@ -127,6 +131,9 @@ jobs: outputs: ${{ github.event_name == 'pull_request' && 'type=cacheonly' || 'type=registry' }} ``` +Pull requests from forks skip this job because they don't have access to the +required secrets. + The example above uses `docker/build-push-action`, which automatically uses the builder set up by `setup-buildx-action`. If you need to use the `docker build` command directly instead, you have two options: @@ -172,6 +179,8 @@ variables: # Build multi-platform image and push to a registry build_push: stage: build + rules: + - if: '$CI_PIPELINE_SOURCE == "push" && $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH' script: - | docker buildx build \ @@ -182,6 +191,8 @@ build_push: # Build an image and discard the result build_cache: stage: build + rules: + - if: '$CI_PIPELINE_SOURCE == "merge_request_event" && $CI_MERGE_REQUEST_SOURCE_PROJECT_PATH == $CI_PROJECT_PATH' script: - | docker buildx build \ @@ -269,7 +280,7 @@ steps: key: build-push plugins: - docker-login#v2.1.0: - username: DOCKER_ACCOUNT + username: "" # replace with your organization name or username password-env: DOCKER_ACCESS_TOKEN # the variable name in the environment hook ```