Correct scanner accounting and verify release packaging #2

Open
gamertan wants to merge 9 commits from sizequeen-scan-hardening into main
3 changed files with 5 additions and 3 deletions
Showing only changes of commit 74b30bbf75 - Show all commits
+1 -1
View File
@@ -20,7 +20,7 @@ jobs:
runs-on: himesan-node24
timeout-minutes: 20
container:
image: sha256:514512270649a85769c2b8ecfcc3a860d3a7da67c29b9b7b1cfe4c75de41d322
image: sha256:271ca1d26057c95a6fd30df7ccc0c053ab394c0e81cd1e4efa182b5b0b60ee97
options: >-
--user 65532:65532
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
+3 -1
View File
@@ -41,7 +41,9 @@ ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-rust188 --format "{
```
Review and update the workflow's image ID after an intentional rebuild; images
stay local to the runner host. No runner labels, global isolation settings or
stay local to the runner host. The image pre-owns `/workspace/gamertan/sized`
for UID 65532 so the runner's workspace setup permits unprivileged checkout.
No runner labels, global isolation settings or
publishing credentials are required. Repository Actions must be enabled.
Only owner-triggered, same-repository code runs on this shared homelab runner.
Source changes on main/the review branch and PRs to main trigger checks;
+1 -1
View File
@@ -5,6 +5,6 @@ RUN rustup component add rustfmt clippy
COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node
# A new runner workspace volume inherits this ownership. No setuid step or
# Docker socket is needed in jobs, even with all capabilities dropped.
RUN mkdir -p /workspace && chown 65532:65532 /workspace
RUN mkdir -p /workspace/gamertan/sized && chown -R 65532:65532 /workspace
USER 65532:65532
WORKDIR /workspace