Container images
Multi-arch images (linux/amd64, linux/arm64) go to three registries on every release and
every commit to main.
Registries
bash
# GitHub Container Registry (primary)
$ docker pull ghcr.io/openwhistle/openwhistle:latest
# Docker Hub
$ docker pull kermit1337/openwhistle:latest
# Quay.io
$ docker pull quay.io/jp1337/openwhistle:latest
Image tags
| Tag | Updated when | Use for |
|---|---|---|
latest |
The highest stable release tag is pushed; never a pre-release (v2.1.0-rc1) |
Production — always points to the current stable release |
1.2.3 / 1.2 / 1 |
Release tag pushed; 1.2 and 1 move only to the highest release in their line |
Pinning to a specific version or minor series |
edge |
Every push to main |
Testing the latest unreleased development state — not for production |
sha-abc1234 |
Every push to main and every release tag |
Reproducing an exact build — useful for debugging and rollback |
Pinning in production
docker-compose.prod.yml pins the image with OPENWHISTLE_VERSION
in .env; its default is the release the file shipped with. The sha- tags suit
immutable infrastructure pipelines.
Image signatures
Every GHCR image is signed with Cosign (keyless, Sigstore). Verify it before pulling in a security-sensitive environment:
bash
$ cosign verify ghcr.io/openwhistle/openwhistle:latest \
--certificate-identity-regexp="https://github.com/openwhistle/OpenWhistle" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"