BookNest already publishes its API image: pull request #14 added publish-image.yml, which Pushing to ghcr.io walks through line by line. It builds the Dockerfile's runtime stage with Buildx 4,514 , logs in to ghcr.io with GITHUB_TOKEN (permissions: packages: write), and pushes ghcr.io/binarybehemoth/booknest tagged with the commit (sha-...), latest on the default branch, and the version on v* tags. Pull requests build without pushing. There is no second image pipeline here; instead, inspect what the first one published, anonymously:
docker buildx imagetools inspect ghcr.io/binarybehemoth/booknest:latestName: ghcr.io/binarybehemoth/booknest:latest
MediaType: application/vnd.oci.image.index.v1+json
Digest: sha256:9246566c71823a0a6ad74c920f9826bcfa153bede3fb86763f34deaf29d81a7a
...
Platform: linux/amd64
...
Platform: unknown/unknown
Annotations:
...
vnd.docker.reference.type: attestation-manifestThe tag points at an OCI index with two entries: the linux/amd64 image, and an unknown/unknown attestation manifest holding the build's provenance, which Buildx adds by default. As with npm 2,036 , pushing from outside Actions needs a classic token (GHCR Alternative), but pulling a public image needs no token at all.