From b0adf9aba2cf004408f193f89d2f8b1821ffc831 Mon Sep 17 00:00:00 2001 From: renovate-bot Date: Mon, 8 Jun 2020 20:42:26 +0000 Subject: [PATCH] Pin Docker digests --- .drone.yml | 4 ++-- Dockerfile | 6 +++--- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.drone.yml b/.drone.yml index 5e3280f..8ece614 100644 --- a/.drone.yml +++ b/.drone.yml @@ -4,7 +4,7 @@ name: build and publish steps: - name: docker - image: plugins/docker + image: plugins/docker@sha256:cfa62987b34ca106a1418afb821f436d957f10a186c7faa27feda781ae7f81fd settings: dockerfile: Dockerfile username: @@ -27,7 +27,7 @@ name: test steps: - name: docker - image: plugins/docker + image: plugins/docker@sha256:cfa62987b34ca106a1418afb821f436d957f10a186c7faa27feda781ae7f81fd settings: dockerfile: Dockerfile repo: mwalbeck/flox diff --git a/Dockerfile b/Dockerfile index 7d34416..0a8442b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM debian:10.3-slim AS prep +FROM debian:10.3-slim@sha256:1ceec96ca567c40500a2745728f7c19c0801785c8b10187b1d66bcd538694fc2 AS prep ENV FLOX_VERSION master RUN set -ex; \ \ @@ -9,14 +9,14 @@ RUN set -ex; \ ; \ git clone --branch $FLOX_VERSION https://github.com/devfake/flox.git /flox; -FROM composer:1.10.6 AS composer +FROM composer:1.10.6@sha256:5c4a8cda7a6cc5035b4725da6ff46be4088d397a9a4d8cf0c2afbfa5dca198f2 AS composer COPY --from=prep /flox /flox RUN set -ex; \ \ cd /flox/backend; \ composer install; -FROM php:7.3.17-fpm-buster +FROM php:7.3.17-fpm-buster@sha256:56dd2c499a2245108ac2f2758ab15f695454d2f1620aaa4d704ec64b4ba8c9a3 COPY --from=composer /flox /usr/share/flox RUN set -ex; \ \ -- 2.45.2