Update #124
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: KatalonDockerCI-NonLatest | |
on: | |
push: | |
branches: | |
- release-for-test | |
permissions: | |
id-token: write # This is required for requesting the JWT | |
contents: read # This is required for actions/checkout | |
jobs: | |
run: | |
name: Run | |
runs-on: ubuntu-latest | |
env: | |
KS_VERSION: 8.5.9 | |
KS_VERSION_TAG: test | |
TEAM: gen4 | |
SERVICE: katalonstudio-docker-vulnerability-reports | |
steps: | |
- name: Checkout | |
uses: actions/checkout@master | |
- name : Prepare docker install | |
run: | | |
curl -fsSL https://get.docker.com -o get-docker.sh | |
sudo sh get-docker.sh | |
sudo apt -y install jq | |
# - name: Build | |
# run: | | |
# chmod u+x ./build/*.sh | |
# ./build/clean.sh $KS_VERSION | |
# ./build/build.sh $KS_VERSION | |
# ./build/tag.sh $KS_VERSION | |
# - name: Test | |
# run: | | |
# chmod u+x ./test/project/*.sh | |
# cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome.sh $KS_VERSION ${{ secrets.API_KEY }} | |
# cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome_root.sh $KS_VERSION ${{ secrets.API_KEY }} | |
# cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome_advanced.sh $KS_VERSION ${{ secrets.API_KEY }} | |
# cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_firefox.sh $KS_VERSION ${{ secrets.API_KEY }} | |
# continue-on-error: true | |
# - uses: azure/docker-login@v1 | |
# with: | |
# login-server: registry.hub.docker.com | |
# username: ${{ secrets.DOCKER_USERNAME }} | |
# password: ${{ secrets.DOCKER_PASSWORD }} | |
# - name: Push to dockerhub | |
# run: | | |
# cd $GITHUB_WORKSPACE | |
# docker login -u ${{ secrets.DOCKER_USERNAME }} -p ${{ secrets.DOCKER_PASSWORD }} docker.io | |
# ./build/tag.sh $KS_VERSION_TAG | |
# ./build/push.sh $KS_VERSION_TAG | |
# - name: Slack Notification | |
# uses: rtCamp/action-slack-notify@master | |
# env: | |
# SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} | |
- name: Scan Security Vulnerabilities | |
run: | | |
chmod u+x ./build/security-report/security_scan.sh | |
./build/security-report/security_scan.sh $KS_VERSION_TAG ${{ secrets.SNYK_AUTH_TOKEN }} | |
- name: Configure aws credentials | |
uses: aws-actions/configure-aws-credentials@v3 | |
with: | |
role-to-assume: arn:aws:iam::${{ vars.AWS_ACCOUNT_ID }}:role/katalon-github-oidc-federation | |
role-session-name: github-actions-${{ env.TEAM }}-${{ env.SERVICE }} | |
aws-region: ${{ vars.AWS_REGION }} | |
- name: Upload Reports to S3 | |
run: | | |
aws s3 cp security_report_trivy.html s3://${{ vars.AWS_S3_BUCKET }}/$KS_VERSION/security_report_trivy.html | |
aws s3 cp security_report_snyk.html s3://${{ vars.AWS_S3_BUCKET }}/$KS_VERSION/security_report_snyk.html | |
working-directory: /home/runner/work/docker-images/docker-images/build/security-report | |