flowchart TB S1["Push to release tag"]:::build S2["Docker Buildx
multi-arch: amd64 + arm64"]:::build S3["GHA Layer Cache"]:::build S4["Build image, attach
Provenance Attestation + SBOM"]:::build S5["Trivy Vulnerability Scan
CRITICAL/HIGH = block"]:::gate Blocked["Release blocked, exit 1"]:::blocked S6["Cosign Image Signing"]:::gate S7["Push ghcr.io/dmccreary/lrs@sha256:...
Immutable Digest Reference"]:::deploy S8["Deployment pulls by digest, never by tag"]:::deploy S1 --> S2 --> S3 --> S4 --> S5 S5 -->|Vulnerabilities found| Blocked S5 -->|Clean scan| S6 --> S7 --> S8 classDef build fill:#2a9d8f,stroke:#1f7a6f,color:#fff,font-size:13px classDef gate fill:#e9a23b,stroke:#b8791f,color:#222,font-size:13px classDef blocked fill:#e05a5a,stroke:#b23b3b,color:#fff,font-size:13px classDef deploy fill:#4c956c,stroke:#2f6b48,color:#fff,font-size:13px linkStyle default stroke:#999,stroke-width:2px

Details

Click a step to see details