Files
frigate/.github/actions/setup/action.yml
T
Josh HawkinsandGitHub 2cb03f442c
CI / AMD64 Extra Build (push) Blocked by required conditions
CI / AMD64 Build (push) Waiting to run
CI / AMD64 Smoke Test (push) Blocked by required conditions
CI / ARM Build (push) Waiting to run
CI / Jetson Jetpack 6 (push) Waiting to run
CI / ARM Extra Build (push) Blocked by required conditions
CI / Synaptics Build (push) Blocked by required conditions
CI / Assemble and push default build (push) Blocked by required conditions
Group dependabot updates (#24624)
* group dependabot updates and hold known-bad versions

Dependabot opened a separate PR for every bump, refilled the list with security PRs right after each merge, and kept proposing versions known to break Frigate.

- Group minor and patch updates and security updates into one PR per ecosystem, with separate groups for packages that only resolve together
- Move every version hold into ignore rules, each with its reason
- Switch to weekly updates with a 3-day cooldown
- Turn off version updates for docker/tensorrt, since no pull request check builds those images
- Drop target-branch, which kept these options from applying to security updates, and the docker entry, which never opened a PR
- Scan the setup composite action, and bump change-string-case, setup-qemu, setup-buildx and login-action

* group github actions security updates
2026-10-10 15:08:01 -05:00

56 lines
1.9 KiB
YAML

name: 'Setup'
description: 'Set up QEMU and Buildx'
inputs:
GITHUB_TOKEN:
required: true
outputs:
image-name:
value: ghcr.io/${{ steps.lowercaseRepo.outputs.lowercase }}:${{ steps.create-short-sha.outputs.SHORT_SHA }}
cache-name:
value: ghcr.io/${{ steps.lowercaseRepo.outputs.lowercase }}:cache
runs:
using: "composite"
steps:
# Stop docker so we can mount more space at /var/lib/docker
- name: Stop docker
run: sudo systemctl stop docker
shell: bash
# This creates a virtual volume at /var/lib/docker to maximize the size
# As of 2/14/2024, this results in 97G for docker images
# Runners no longer have a separate /mnt disk, so the temp PV is also carved
# from root and temp-reserve-mb is what actually stays free on root. Keep 4G
# there for setup-qemu/buildx caches in ~/.docker and the tool cache
- name: Maximize build space
uses: easimon/maximize-build-space@master
with:
root-reserve-mb: 8192
temp-reserve-mb: 4096
remove-dotnet: 'true'
remove-android: 'true'
remove-haskell: 'true'
remove-codeql: 'true'
build-mount-path: '/var/lib/docker'
- name: Start docker
run: sudo systemctl start docker
shell: bash
- id: lowercaseRepo
uses: ASzc/change-string-case-action@v8
with:
string: ${{ github.repository }}
- name: Set up QEMU
uses: docker/setup-qemu-action@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Log in to the Container registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ inputs.GITHUB_TOKEN }}
- name: Create version file
run: make version
shell: bash
- id: create-short-sha
run: echo "SHORT_SHA=${GITHUB_SHA::7}" >> $GITHUB_OUTPUT
shell: bash