CO-3006: Create Studio harden image based on ubuntu 20.04 (remove gos… #1
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: KatalonDockerCI Harden | |
on: | |
workflow_dispatch: | |
inputs: | |
KS_VERSION: | |
description: 'Katalon Studio version (E.g: "9.5.0")' | |
required: false | |
default: 9.5.0 | |
KS_VERSION_TAG: | |
description: 'Katalon Studio version tag (E.g: "9.5.0")' | |
required: false | |
default: 9.5.0 | |
KS_VERSION_LATEST_TAG: | |
description: 'Katalon Studio latest version tag (E.g: "9-latest")' | |
required: false | |
default: 9-latest | |
push: | |
branches: | |
- master | |
jobs: | |
run: | |
name: Run | |
runs-on: ubuntu-latest | |
env: | |
KS_VERSION: ${{ inputs.KS_VERSION }} | |
KS_VERSION_TAG: ${{ inputs.KS_VERSION_TAG }} | |
KS_VERSION_LATEST_TAG: ${{ inputs.KS_VERSION_LATEST_TAG }} | |
steps: | |
- name: Checkout | |
uses: actions/checkout@master | |
- name : Prepare docker install | |
run: | | |
curl -fsSL https://get.docker.com -o get-docker.sh | |
sudo sh get-docker.sh | |
sudo apt -y install jq | |
- name: Prepare | |
run: | | |
chmod u+x ./build/*.sh | |
./build/prevent_overwrite_existing_tag.sh $KS_VERSION_TAG | |
- name: Build | |
run: | | |
chmod u+x ./build/*.sh | |
./build/clean.sh $KS_VERSION | |
./build/build-harden.sh $KS_VERSION | |
./build/tag.sh $KS_VERSION | |
- name: Test | |
run: | | |
chmod u+x ./test/project/*.sh | |
cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome.sh $KS_VERSION ${{ secrets.API_KEY }} | |
cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome_root.sh $KS_VERSION ${{ secrets.API_KEY }} | |
cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_chrome_advanced.sh $KS_VERSION ${{ secrets.API_KEY }} | |
cd $GITHUB_WORKSPACE/test/project && rm -rfv ./bin && ./run_firefox.sh $KS_VERSION ${{ secrets.API_KEY }} | |
continue-on-error: true | |
- uses: azure/docker-login@v1 | |
with: | |
login-server: registry.hub.docker.com | |
username: ${{ secrets.DOCKER_USERNAME }} | |
password: ${{ secrets.DOCKER_PASSWORD }} | |
- name: Push to dockerhub | |
run: | | |
cd $GITHUB_WORKSPACE | |
docker login -u ${{ secrets.DOCKER_USERNAME }} -p ${{ secrets.DOCKER_PASSWORD }} docker.io | |
./build/tag.sh $KS_VERSION_TAG | |
./build/push.sh $KS_VERSION_TAG | |
./build/tag.sh $KS_VERSION_LATEST_TAG | |
./build/push.sh $KS_VERSION_LATEST_TAG | |
- name: Slack Notification | |
uses: rtCamp/action-slack-notify@master | |
env: | |
SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} | |
- name: Scan Security Vulnerabilities | |
run: | | |
chmod u+x ./build/security-report/security_scan.sh | |
./build/security-report/security_scan.sh $KS_VERSION_TAG ${{ secrets.SNYK_AUTH_TOKEN }} | |
- name: Upload reports | |
run: | | |
chmod u+x ./build/security-report/upload.sh | |
./build/security-report/upload.sh $KS_VERSION ${{ secrets.SEC_AWS_S3_BUCKET }} ${{ secrets.SEC_AWS_ACCESS_KEY_ID }} ${{ secrets.SEC_AWS_SECRET_ACCESS_KEY }} |