-
Notifications
You must be signed in to change notification settings - Fork 44
205 lines (173 loc) · 5.3 KB
/
Copy pathvalidations.yaml
File metadata and controls
205 lines (173 loc) · 5.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
name: "Validations"
on:
workflow_dispatch:
push:
branches:
- main
pull_request:
permissions: {}
jobs:
Static-Analysis:
# Note: changing this job name requires making the same update in the .github/workflows/release.yaml pipeline
name: "Static analysis"
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
- name: Run static analysis
run: make static-analysis
Build:
# Note: changing this job name requires making the same update in the .github/workflows/release.yaml pipeline
#
# ensure dist/ is up-to-date with src/ — protects against forgetting to run the
# pre-commit hook that bundles the action.
name: "Build"
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
- name: Build action distributable
run: make build
- name: Verify dist/ is up-to-date
run: |
git status --porcelain
git diff --exit-code
Unit-Test:
# Note: changing this job name requires making the same update in the .github/workflows/release.yaml pipeline
name: "Unit tests"
runs-on: ubuntu-24.04
permissions:
contents: read
services:
registry:
image: registry:2
ports:
- 5000:5000
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
- name: Build fixture images
run: |
for distro in alpine centos debian; do
docker build -t localhost:5000/match-coverage/$distro ./tests/fixtures/image-$distro-match-coverage
docker push localhost:5000/match-coverage/${distro}:latest
done
- name: Run unit tests
run: make unit
Action-Fixtures-Linux:
name: "Action fixtures (Linux)"
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
path: ./
persist-credentials: false
- uses: ./
with:
path: ./tests/fixtures/npm-project
artifact-name: linux-1.spdx
- uses: ./
with:
path: ./tests/fixtures/yarn-project
artifact-name: linux-2.spdx
- uses: ./
id: yarn-scan
with:
path: ./tests/fixtures/yarn-project
artifact-name: linux-3.spdx
- uses: ./
with:
path: ./tests/fixtures/yarn-project
artifact-name: linux-SBOM.txt
Action-Fixtures-Windows:
name: "Action fixtures (Windows)"
runs-on: windows-latest
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
path: ./
persist-credentials: false
- uses: ./
with:
path: ./tests/fixtures/npm-project
artifact-name: windows-1.spdx
- uses: ./
with:
path: ./tests/fixtures/yarn-project
artifact-name: windows-2.spdx
- uses: ./
id: yarn-scan
with:
path: ./tests/fixtures/yarn-project
artifact-name: windows-3.spdx
- uses: ./
with:
path: ./tests/fixtures/yarn-project
artifact-name: windows-SBOM.txt
Action-Smoke-Test:
name: "Action smoke test"
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
path: ./
persist-credentials: false
- uses: ./download-syft # anchore/sbom-action/download-syft
id: syft
- env:
SYFT_CMD: ${{ steps.syft.outputs.cmd }}
run: |
echo "$SYFT_CMD"
"$SYFT_CMD" dir:.
- uses: ./ # anchore/sbom-action
id: dirscan
with:
artifact-name: dirscan-sbom.spdx
output-file: dirscan-sbom.spdx
format: spdx
- run: |
echo DIR SCAN SBOM:
cat dirscan-sbom.spdx
- uses: ./ # anchore/sbom-action
id: imagescan
with:
image: alpine:latest
artifact-name: imagescan-sbom.spdx
output-file: my.sbom
- run: |
echo IMAGE SCAN SBOM:
cat my.sbom
- uses: ./publish-sbom # anchore/sbom-action/publish-sbom
with:
sbom-artifact-match: imagescan-sbom.spdx
- uses: ./publish-sbom # anchore/sbom-action/publish-sbom
with:
sbom-artifact-match: "^dont-match-anything$"
- uses: ./ # anchore/sbom-action with artifact retention
name: "One day artifact retention test"
id: one-day
with:
image: alpine:latest
upload-artifact-retention: 1
artifact-name: one-day.sbom.spdx
output-file: one-day-sbom.spdx
format: spdx