scripts/new-post.mjs writes schema-valid posts from flags or a JSON event (the IaC publish seam). Gitea Actions workflow: ci check, audit-ci gate, build, dist scan, CycloneDX SBOM, buildah build+push, and a least-privilege digest-bump PR to home-ops (never auto-merged). Renovate + audit allowlist.
This commit is contained in:
@@ -11,7 +11,7 @@
|
||||
set -euo pipefail
|
||||
|
||||
REGISTRY="${REGISTRY:-git.bztmon.com}"
|
||||
IMAGE="${IMAGE:-jwrong96/bztmon-site}"
|
||||
IMAGE="${IMAGE:-jwright/bztmon-site}"
|
||||
REF="${REGISTRY}/${IMAGE}"
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
Reference in New Issue
Block a user