Builds and pushes the pass-cli image to code.aneur.in on every push to
main, based on zampler/zampler's build.yml pattern (registry login,
promote current latest to previous, build and push). Dropped everything
specific to that repo's own build (frontend/npm, Go cross-compilation,
multi-arch buildx) since this repo just builds one Dockerfile for one
architecture.
Uses its own BUILD_API_TOKEN secret, unrelated to Proton Pass -- build
workflows in this org are configured per-repo and don't go through
pass-cli, which is only for 'real world' deploy-time credentials.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Prebuilt glibc image for pass-cli: a small debian:bookworm-slim base with
a pinned, checksum-verified pass-cli binary, published so Alpine/musl-based
CI jobs can pull and run it without hitting missing glibc symbols
(fcntl64, __res_init, etc, which gcompat/libc6-compat don't shim).
No ENTRYPOINT, just CMD ["pass-cli"] -- callers running their own script
against pass-cli mount it in and pass it as the command directly
(`docker run image sh /script.sh`), no --entrypoint override needed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>