name: Build & Publish to GitHub Container Registry

on:
  push:
    branches: [ main ]
    tags: ['v*.*.*']
    
permissions:
  contents: read
  packages: write

jobs:
  build-and-push:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout repository
        uses: actions/checkout@v4

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v3

      - name: Log in to GitHub Container Registry
        uses: docker/login-action@v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Generate package-lock.json
        run: npm install --package-lock-only

      - name: Build and push image
        uses: docker/build-push-action@v6
        with:
          context: .
          push: true
          tags: |
            ghcr.io/galihru/pqcrypto:${{ github.ref_name }}
            ghcr.io/galihru/pqcrypto:latest
