Pushing to GHCR

Pushing an Image to the GitHub Container Registry

BookNest already publishes its API image: pull request #14 added publish-image.yml, which Pushing to ghcr.io walks through line by line. It builds the Dockerfile's runtime stage with Buildx 4,514 , logs in to ghcr.io with GITHUB_TOKEN (permissions: packages: write), and pushes ghcr.io/binarybehemoth/booknest tagged with the commit (sha-...), latest on the default branch, and the version on v* tags. Pull requests build without pushing. There is no second image pipeline here; instead, inspect what the first one published, anonymously:

Inspecting BookNest's published image without logging inShell
docker buildx imagetools inspect ghcr.io/binarybehemoth/booknest:latest
Output
Name:      ghcr.io/binarybehemoth/booknest:latest
MediaType: application/vnd.oci.image.index.v1+json
Digest:    sha256:9246566c71823a0a6ad74c920f9826bcfa153bede3fb86763f34deaf29d81a7a
...
  Platform:    linux/amd64
...
  Platform:    unknown/unknown
  Annotations:
...
    vnd.docker.reference.type:   attestation-manifest

The tag points at an OCI index with two entries: the linux/amd64 image, and an unknown/unknown attestation manifest holding the build's provenance, which Buildx adds by default. As with npm 2,036 , pushing from outside Actions needs a classic token (GHCR Alternative), but pulling a public image needs no token at all.