From 93681ed3162c63c466eab189559401f47a708640 Mon Sep 17 00:00:00 2001 From: Lucifix <4372997+Lucifix@users.noreply.github.com> Date: Tue, 15 Sep 2026 20:19:04 +0200 Subject: [PATCH] fix: read metadata tags from step output in manifest merge The merge step jq'd DOCKER_METADATA_OUTPUT_JSON using the bake-file path (.target."docker-metadata-action".tags), which is null for that env var. imagetools create then got no -t flags and failed with "can't push with no tags specified", so main never got tagged on GHCR and the Docker Hub mirror never ran. Read steps.meta.outputs.tags directly and fail loudly if empty. --- .github/workflows/docker-publish.yml | 24 ++++++++++++++++++------ 1 file changed, 18 insertions(+), 6 deletions(-) diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 2411e30..cb0aaac 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -142,13 +142,25 @@ jobs: - name: Create multi-arch manifest working-directory: /tmp/digests + env: + TAGS: ${{ steps.meta.outputs.tags }} run: | - # Word splitting is deliberate here: the first substitution expands - # to "-t tag -t tag ...", the second to one ref per digest file. - # shellcheck disable=SC2046 - docker buildx imagetools create \ - $(jq -cr '.target."docker-metadata-action".tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ - $(printf '${{ env.IMAGE }}@sha256:%s ' *) + # Read the newline-separated tags output directly rather than + # jq-ing DOCKER_METADATA_OUTPUT_JSON: that env var's shape is not + # the bake-file layout, and a wrong path yields zero tags, which + # imagetools rejects ("can't push with no tags specified"). + args=() + while read -r tag; do + [ -n "$tag" ] && args+=(-t "$tag") + done <<< "$TAGS" + if [ ${#args[@]} -eq 0 ]; then + echo "::error::docker/metadata-action produced no tags for ${GITHUB_REF}" + exit 1 + fi + for digest in *; do + args+=("${IMAGE}@sha256:${digest}") + done + docker buildx imagetools create "${args[@]}" # The secrets context is not available in `if:` expressions, so # presence has to be probed in a shell step and passed on as an output.