---
title: Use GitHub Actions for validated builds
description: Use GitHub actions for validated builds
image: https://codenotary.com/hubfs/Imported_Blog_Media/Blog-Default-MnL-Feb-10-2023-08-07-17-2504-AM.jpg
---

**$ protect --distro linux --machines 25 --free**

[Start now](https://apps.codenotary.com/linux)

[![cn-logo-black-nobg](https://codenotary.com/hubfs/cn-logo-black-nobg.svg)](https://codenotary.com/)

- Product
  
  #### [![AgentMon Start](https://codenotary.com/hubfs/chub_backup/AgentMon%20Start.svg) **AgentMon Start** See what your AI agents are doing on your machine. TRY NOW →](https://codenotary.com/agentmon-start)
  
  #### [![AgentMon for Enterprise](https://codenotary.com/hubfs/AgentMon%20for%20Enterprise.svg) **AgentMon** Currently monitors more \> 7 million agent interactions/day. TRY NOW →](https://codenotary.com/agentmon)
  
  #### [![AgentX](https://codenotary.com/hubfs/AgentX.svg) **AgentX** Agentic network control middleware. TRY NOW →](https://codenotary.com/agent-network-control)
  
  #### [![Autonomous Security](https://codenotary.com/hubfs/Autonomous%20Security.svg) **Autonomous Security** AI Agents keep your servers secure. TRY NOW →](https://codenotary.com/trust)
- Use Cases
  
  #### [**AI Agent Risk Monitoring** Continuous oversight of autonomous agents across every environment.](https://codenotary.com/use-cases#risk)
  
  #### [**Autonomous Security Operations** Self-healing defenses that detect, contain, and remediate threats.](https://codenotary.com/use-cases#agentops)
  
  #### [**AI Coding Governance & Performance Monitoring** AI-generated code reviewed, tracked, and held to quality standards.](https://codenotary.com/use-cases#performance)
  
  #### [**AI Tool Cost & Usage Optimization** Spend and consumption optimized across every AI service in use.](https://codenotary.com/use-cases#cost)
  
  #### [**AI Tool Security & Policy Enforcement** Approved AI usage enforced with guardrails and policy controls.](https://codenotary.com/use-cases#security#security)
  
  #### [**Shadow AI Governance** Unsanctioned AI tools discovered, surfaced, and brought under control.](https://codenotary.com/use-cases#shadowit)
- [Blog](https://codenotary.com/blog)
- [Press](https://codenotary.com/press)
- Resources
  
  #### [**Integrations** Connect with your favorite tools and platforms. LEARN MORE →](https://codenotary.com/integrations)
  
  #### [**Support** Get help from our dedicated support team. GET HELP →](https://support.codenotary.com)
  
  #### [**Success Stories** Read how customers achieve their goals. READ MORE →](https://codenotary.com/success)
  
  #### [**Learn** Access documentation and learning resources. EXPLORE →](https://codenotary.com/learn)

[Login](https://apps.codenotary.com/auth/login)

[All posts](https://codenotary.com/blog/all)

 Nov 25, 2019

# use-github-actions-for-validated-builds

 By  [Dennis](https://codenotary.com/blog/author/dennis)  ·   2 minute read

[GitHub Actions](https://github.com/features/actions) provide a very simple way for GitOps pipelines as you don’t need an additional CI/CD tool. You could simply create or use an existing GitHub actions and configure it to run whenever a specific branch is updated.

You can make sure, that every build (i. e. a container image) can be validated in the most secure way, Codenotary notarization is mandatory.

Let’s walk through the simple steps to integrate Codenotary:

## Create GitHub secrets

You can start by adding GitHub secrets for Dockerhub and Codenotary in your repository.

![](https://codenotary.com/hubfs/Imported_Blog_Media/secrets-1024x696-1-1.png)

If you have no free Codenotary account yet to setup the notarization process, start with that:

[**Codenotary Sign Up**](https://dashboard.Codenotary.io/auth/signup)

## Create your workflow

GitHub Actions are defined using workflows that can either be created as files in your repository under .github/workflows or using the UI and the Actions menu.

## The workflow

The following workflow will be triggered whenever a new commit in the master branch is detected, builds a container image, notarizes the image and pushes it to [Dockerhub.com](https://hub.docker.com/).

Please make sure to replace the Container Image Path with your account repository.

![GitHub Actions yml](https://codenotary.com/hubfs/Imported_Blog_Media/action_yml_-1024x539-1-1.png)

```
# Define when the Actions should be triggered
on:
  push:
    branches:
      - master
    tags:
      - "**"
# Name of the Workflow
name: "Continuous Deployment"

# Different Jobs
jobs:
  build:
    name: "Build and deploy"
    runs-on: ubuntu-latest # Define the build docker image

    env:
      DOCKER_IMAGE: dzlabsch/build-notarize-docker-action # define Docker Repo

    steps:
# Checkout the Git repo
      - name: "Checkout"
        uses: actions/checkout@v1.0.0  

# Build the container image as latest
      - name: "Build Docker image"
        run: $(which docker) build --tag ${DOCKER_IMAGE}:latest .

# Download and verify Codenotary vcn
      - name: "Download vcn"
        run: |
             curl -L -o /tmp/vcn https://github.com/vchain-us/vcn/releases/download/v0.7.3/vcn-v0.7.3-linux-amd64-static
             CHECKSUM=$(sha256sum /tmp/vcn | cut -d " " -f 1)
             echo $CHECKSUM
             curl -s https://api.Codenotary.io/authenticate/$CHECKSUM?org=vchain.us | grep -q :0
             chmod +x /tmp/vcn

# Notarize the container image using your GitHub secrets
      - name: "Notarize Docker Image"
        run: |
             VCN_USER=$  VCN_PASSWORD=$ /tmp/vcn login
             VCN_NOTARIZATION_PASSWORD=$ /tmp/vcn n -p --attr GitHub="${GITHUB_SHA:0:7}" docker://${DOCKER_IMAGE}:latest 

# Log into Dockerhub or your container registry
      - name: "Docker Login"
        if: "'refs/heads/master' == github.ref || startsWith(github.ref, 'refs/tags/')"
        run: echo $ | $(which docker) login --password-stdin --username $

# Push the container image to the container repository
      - name: "Push Docker image (latest)"
        if: "'refs/heads/master' == github.ref || startsWith(github.ref, 'refs/tags/')"
        run: $(which docker) push ${DOCKER_IMAGE}:latest

# Logout Docker registry
      - name: "Docker Logout"
        if: "'refs/heads/master' == github.ref || startsWith(github.ref, 'refs/tags/')"
        run: $(which docker) logout
```

## Check the Workflow

When you commit the next changes to the master branch the GitHub action workflow should automatically be triggered.

![](https://codenotary.com/hubfs/Imported_Blog_Media/checkwf-1024x315-1-1.png)

successful GitHub Action workflow

When you click the title of the workflow, you can also check the details of the different steps.

![GitHub Action job overview](https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png)

and you can open each job individual to check the details:

![Codenotary Notary action](https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png)

## Authenticate the container image

Everyone downloading and using that notarized container image can check the authenticity of it using [Codenotary vcn](https://github.com/vchain-us/vcn) (***vcn authenticate docker://image***).

It could also be easily integrated in your deployment process as well.

[![Share on twitter](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/twitter-color.png?width=35&height=35&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://codenotary.com/blog/use-github-actions-for-validated-builds&utm_medium=social&utm_source=twitter&url=https://codenotary.com/blog/use-github-actions-for-validated-builds&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/facebook-color.png?width=35&height=35&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://codenotary.com/blog/use-github-actions-for-validated-builds&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/linkedin-color.png?width=35&height=35&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://codenotary.com/blog/use-github-actions-for-validated-builds&utm_medium=social&utm_source=linkedin) [![Share on pinterest](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/pinterest.jpg?width=35&height=35&name=pinterest.jpg)](http://pinterest.com/pin/create/button/?url=https://codenotary.com/blog/use-github-actions-for-validated-builds&utm_medium=social&utm_source=pinterest&media=)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Dennis",
    "url" : "https://codenotary.com/blog/author/dennis"
  },
  "dateModified" : "2024-05-01T07:46:29.610Z",
  "datePublished" : "2019-11-25T22:41:31.000Z",
  "headline" : "Use GitHub Actions for validated builds",
  "image" : [ "https://codenotary.com/hubfs/Imported_Blog_Media/Blog-Default-MnL-Feb-10-2023-08-07-17-2504-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://codenotary.com/blog/use-github-actions-for-validated-builds",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://codenotary.com/hubfs/logo-light.svg"
    },
    "name" : "Codenotary, Inc."
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "Dennis" ],
    "url" : "https://codenotary.com/blog/author/dennis"
  },
  "datePublished" : "2019-11-25T22:41:31+0000",
  "description" : "Use GitHub actions for validated builds",
  "headline" : "use-github-actions-for-validated-builds",
  "image" : "https://23873599.fs1.hubspotusercontent-na1.net/hubfs/23873599/Imported_Blog_Media/Blog-Default-MnL-Feb-10-2023-08-07-17-2504-AM.jpg",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/23873599/logo-light.svg"
    },
    "name" : ""
  },
  "url" : "https://codenotary.com/blog/use-github-actions-for-validated-builds"
}
```