ARG ALPINE_VERSION=1.0.0-alpine-3.23.3 FROM git.dzuchun.ing/actions/alpine:$ALPINE_VERSION AS builder ENV PATH="/root/.cargo/bin:/usr/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" # update package registry, install # - deps necessary(?) to build-std on musl # - upx RUN apk update; \ apk add --no-cache musl-dev; \ apk add --no-cache gcc; \ apk add --no-cache upx; \ apk cache clean; # install Rust RUN apk add --no-cache curl; \ curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > rustup.sh; \ chmod +x rustup.sh; \ ./rustup.sh -c cargo --profile minimal -y; \ rustup -v toolchain install nightly --profile minimal; \ rustup -v +nightly component remove rust-docs || true; \ rustup -v +nightly component remove clippy || true; \ rustup -v +nightly component remove rustfmt || true; \ rustup -v +nightly component remove llvm-tools || true; \ rustup -v +nightly component add rust-src || true; # build-std needs this component \ rustup +nightly component list; \ apk del curl; # build cargo-audit RUN git clone --branch main --depth 1 https://github.com/rustsec/rustsec.git /rustsec; \ cd /rustsec; \ RUSTFLAGS='-C lto -C strip=symbols -C opt-level=s -C embed-bitcode=yes -C panic=abort -C incremental=false -C codegen-units=1 -Z dylib-lto' cargo +nightly build -Zbuild-std=std,panic_abort --release -p cargo-audit --verbose; \ upx --ultra-brute ./target/release/cargo-audit; \ mv ./target/release/cargo-audit /; # add separate step to avoid making layers FROM git.dzuchun.ing/actions/alpine:$ALPINE_VERSION COPY --from=builder /cargo-audit / # labels LABEL org.opencontainers.image.source=https://git.dzuchun.ing/actions/cargo-audit