Container images

Multi-arch images (linux/amd64, linux/arm64) go to three registries on every release and every commit to main.

Registries

bash
# GitHub Container Registry (primary)
$ docker pull ghcr.io/openwhistle/openwhistle:latest

# Docker Hub
$ docker pull kermit1337/openwhistle:latest

# Quay.io
$ docker pull quay.io/jp1337/openwhistle:latest

Image tags

Tag Updated when Use for
latest The highest stable release tag is pushed; never a pre-release (v2.1.0-rc1) Production — always points to the current stable release
1.2.3 / 1.2 / 1 Release tag pushed; 1.2 and 1 move only to the highest release in their line Pinning to a specific version or minor series
edge Every push to main Testing the latest unreleased development state — not for production
sha-abc1234 Every push to main and every release tag Reproducing an exact build — useful for debugging and rollback
Pinning in production

docker-compose.prod.yml pins the image with OPENWHISTLE_VERSION in .env; its default is the release the file shipped with. The sha- tags suit immutable infrastructure pipelines.

Image signatures

Every GHCR image is signed with Cosign (keyless, Sigstore). Verify it before pulling in a security-sensitive environment:

bash
$ cosign verify ghcr.io/openwhistle/openwhistle:latest \
    --certificate-identity-regexp="https://github.com/openwhistle/OpenWhistle" \
    --certificate-oidc-issuer="https://token.actions.githubusercontent.com"

Edit this page on GitHub