-
Notifications
You must be signed in to change notification settings - Fork 0
129 lines (107 loc) · 3.22 KB
/
Copy pathci.yml
File metadata and controls
129 lines (107 loc) · 3.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
name: CI
on:
pull_request:
push:
branches:
- main
tags:
- "v*.*.*"
permissions:
contents: read
packages: write
id-token: write
env:
IMAGE_NAME: ghcr.io/${{ github.repository }}
PYTHON_VERSION: "3.14"
POETRY_VERSION: "2.4.1"
jobs:
verify:
name: Test and lint
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install Poetry
run: pipx install poetry==${{ env.POETRY_VERSION }}
- name: Configure Poetry cache
uses: actions/cache@v4
with:
path: ~/.cache/pypoetry
key: poetry-${{ runner.os }}-${{ env.PYTHON_VERSION }}-${{ hashFiles('poetry.lock') }}
restore-keys: |
poetry-${{ runner.os }}-${{ env.PYTHON_VERSION }}-
- name: Install dependencies
run: poetry install --with dev --no-interaction --no-ansi --no-root
- name: Run secret scanning
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Run lint
run: poetry run ruff check src tests scripts
- name: Run tests
run: poetry run pytest -q
docker:
name: Build, sign, and publish image
runs-on: ubuntu-latest
needs: verify
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GHCR
if: github.event_name == 'push'
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=ref,event=tag
type=sha,prefix=sha-
- name: Build and push image
id: build
uses: docker/build-push-action@v6
with:
context: .
target: runtime
push: ${{ github.event_name == 'push' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Generate SBOM
if: github.event_name == 'push'
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }}
format: cyclonedx
output: sbom.cyclonedx.json
- name: Upload SBOM
if: github.event_name == 'push'
uses: actions/upload-artifact@v4
with:
name: sbom
path: sbom.cyclonedx.json
- name: Install cosign
if: github.event_name == 'push'
uses: sigstore/cosign-installer@v3
- name: Sign container image
if: github.event_name == 'push'
env:
DIGEST: ${{ steps.build.outputs.digest }}
run: |
cosign sign --yes \
"${{ env.IMAGE_NAME }}@${DIGEST}"