diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml deleted file mode 100644 index 65151a0..0000000 --- a/.github/workflows/ci.yml +++ /dev/null @@ -1,44 +0,0 @@ -name: ci - -on: - push: - branches: - - main - pull_request_target: - branches: - - main - -concurrency: - group: ${{ github.workflow }}-${{ github.event_name == 'push' && github.run_number || github.event.pull_request.number }} - cancel-in-progress: true - -jobs: - test: - name: Run Tests - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v3 - with: - fetch-depth: 0 - - - name: Setup Go - uses: actions/setup-go@v4 - with: - go-version: '1.18.0' - - - name: Go mod - run: go mod tidy - - - name: Execute tests - run: go test -coverprofile=coverage.out -count=1 ./... - - - name: SonarQube Scan - uses: SonarSource/sonarcloud-github-action@v1.9.1 - env: - SONAR_TOKEN: ${{ secrets.SONARQUBE_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - projectBaseDir: . - args: > - -Dsonar.host.url=${{ secrets.SONARQUBE_HOST }} diff --git a/.github/workflows/update-license-year.yml b/.github/workflows/update-license-year.yml deleted file mode 100644 index deb90b4..0000000 --- a/.github/workflows/update-license-year.yml +++ /dev/null @@ -1,46 +0,0 @@ -name: Update License Year - -on: - schedule: - - cron: "0 3 1 1 *" # 03:00 AM on January 1 - -permissions: - contents: write - pull-requests: write - -jobs: - license: - name: Update license - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v3 - with: - fetch-depth: 0 - - - name: Set Current year - run: "echo CURRENT=$(date +%Y) >> $GITHUB_ENV" - - - name: Set Previous Year - run: "echo PREVIOUS=$(($CURRENT-1)) >> $GITHUB_ENV" - - - name: Update LICENSE - uses: jacobtomlinson/gha-find-replace@v3 - with: - find: ${{ env.PREVIOUS }} - replace: ${{ env.CURRENT }} - include: "LICENSE" - regex: false - - - name: Commit files - run: | - git config user.name 'github-actions[bot]' - git config user.email 'github-actions[bot]@users.noreply.github.com' - git commit -m "Updated License Year" -a - - - name: Create Pull Request - uses: peter-evans/create-pull-request@v5 - with: - token: ${{ secrets.GITHUB_TOKEN }} - title: Update License Year - branch: update-license diff --git a/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci.yaml b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci.yaml new file mode 100644 index 0000000..f8ede5e --- /dev/null +++ b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci.yaml @@ -0,0 +1,131 @@ +pipeline: + name: gincache_ci + identifier: gincache_ci + projectIdentifier: Harness_Split + orgIdentifier: PROD + tags: {} + properties: + ci: + codebase: + connectorRef: fmegithubrunnersci + repoName: gincache + build: <+input> + depth: 0 + stages: + - stage: + name: CI + identifier: CI + type: CI + spec: + cloneCodebase: true + caching: + enabled: true + platform: + os: Linux + arch: Amd64 + runtime: + type: Cloud + spec: + size: flex + execution: + steps: + - step: + identifier: test + name: Run Tests + type: Run + spec: + connectorRef: dockerhub + image: golang:1.18 + shell: Bash + command: |- + go mod tidy + go test -coverprofile=coverage.out -count=1 ./... + - step: + identifier: sonarqube_analysis + name: SonarQube Analysis + type: Run + spec: + connectorRef: dockerhub + image: golang:1.18 + shell: Bash + command: |- + apt-get update -qq && apt-get install -y -qq --no-install-recommends unzip + export SONAR_SCANNER_VERSION=6.2.1.4610 + curl -sSLo sonar-scanner.zip "https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}-linux-x64.zip" + unzip -q sonar-scanner.zip + export PATH="$(pwd)/sonar-scanner-${SONAR_SCANNER_VERSION}-linux-x64/bin:$PATH" + + SONAR_EXTRA_ARGS="" + if [ "<+codebase.build.type>" = "PR" ]; then + SONAR_EXTRA_ARGS="-Dsonar.pullrequest.key=<+codebase.prNumber> \ + -Dsonar.pullrequest.branch=<+codebase.sourceBranch> \ + -Dsonar.pullrequest.base=<+codebase.targetBranch>" + elif [ "<+codebase.branch>" != "main" ]; then + SONAR_EXTRA_ARGS="-Dsonar.branch.name=<+codebase.branch>" + fi + + sonar-scanner \ + -Dsonar.host.url="https://sonar.harness.io/" \ + -Dsonar.token="${SONAR_TOKEN}" \ + -Dsonar.projectName=gincache \ + -Dsonar.projectKey=gincache \ + -Dsonar.sources=. \ + -Dsonar.tests=. \ + -Dsonar.test.inclusions="**/*_test.go" \ + -Dsonar.go.coverage.reportPaths=coverage.out \ + -Dsonar.coverage.exclusions="**/mocks/**" \ + -Dsonar.cpd.exclusions="**/*_test.go" \ + -Dsonar.links.ci="https://github.com/splitio/gincache/actions" \ + -Dsonar.links.scm="https://github.com/splitio/gincache" \ + ${SONAR_EXTRA_ARGS} + envVariables: + SONAR_TOKEN: <+secrets.getValue("sonarqube-token")> + - step: + identifier: post_quality_gate + name: Post Quality Gate + type: Run + spec: + connectorRef: dockerhub + image: golang:1.18 + shell: Bash + command: |- + REPORT_FILE=".scannerwork/report-task.txt" + if [ ! -f "$REPORT_FILE" ]; then + echo "ERROR: $REPORT_FILE not found." + exit 1 + fi + CE_TASK_URL=$(grep "ceTaskUrl" "$REPORT_FILE" | cut -d'=' -f2-) + + MAX_RETRIES=30; RETRY_INTERVAL=10; TASK_STATUS="PENDING" + for i in $(seq 1 $MAX_RETRIES); do + echo "Attempt $i/$MAX_RETRIES - checking analysis task..." + TASK_RESPONSE=$(curl -s -u "${SONAR_TOKEN}:" "$CE_TASK_URL") + TASK_STATUS=$(echo "$TASK_RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['task']['status'])" 2>/dev/null || echo "UNKNOWN") + echo "Task status: $TASK_STATUS" + [ "$TASK_STATUS" = "SUCCESS" ] || [ "$TASK_STATUS" = "FAILED" ] || [ "$TASK_STATUS" = "CANCELLED" ] && break + sleep $RETRY_INTERVAL + done + if [ "$TASK_STATUS" != "SUCCESS" ]; then + echo "Analysis task did not complete: $TASK_STATUS"; exit 1 + fi + + ANALYSIS_ID=$(echo "$TASK_RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['task']['analysisId'])") + QG_RESPONSE=$(curl -s -u "${SONAR_TOKEN}:" "https://sonar.harness.io/api/qualitygates/project_status?analysisId=${ANALYSIS_ID}") + QG_STATUS=$(echo "$QG_RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['projectStatus']['status'])") + echo "Quality Gate Status: $QG_STATUS" + + case "$QG_STATUS" in + OK) GH_STATE="success"; DESC="Quality gate passed" ;; + ERROR) GH_STATE="failure"; DESC="Quality gate failed" ;; + WARN) GH_STATE="success"; DESC="Quality gate passed with warnings" ;; + *) GH_STATE="failure"; DESC="Quality gate status: $QG_STATUS" ;; + esac + + curl -s -X POST \ + -H "Authorization: token ${GITHUB_TOKEN}" \ + -H "Accept: application/vnd.github.v3+json" \ + "https://api.github.com/repos/splitio/gincache/statuses/<+codebase.commitSha>" \ + -d "{\"state\":\"${GH_STATE}\",\"description\":\"${DESC}\",\"context\":\"sonarqube/quality-gate\",\"target_url\":\"https://sonar.harness.io/dashboard?id=gincache\"}" + envVariables: + SONAR_TOKEN: <+secrets.getValue("sonarqube-token")> + GITHUB_TOKEN: <+secrets.getValue("fme-github-netrc-token")> diff --git a/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_pr.yaml b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_pr.yaml new file mode 100644 index 0000000..0c6ed1c --- /dev/null +++ b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_pr.yaml @@ -0,0 +1,14 @@ +inputSet: + name: gincache_ci_pr + identifier: gincache_ci_pr + orgIdentifier: PROD + projectIdentifier: Harness_Split + pipeline: + identifier: gincache_ci + properties: + ci: + codebase: + build: + type: PR + spec: + number: <+trigger.prNumber> diff --git a/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_push.yaml b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_push.yaml new file mode 100644 index 0000000..6221b60 --- /dev/null +++ b/.harness/orgs/PROD/projects/Harness_Split/pipelines/gincache_ci/input_sets/gincache_ci_push.yaml @@ -0,0 +1,14 @@ +inputSet: + name: gincache_ci_push + identifier: gincache_ci_push + orgIdentifier: PROD + projectIdentifier: Harness_Split + pipeline: + identifier: gincache_ci + properties: + ci: + codebase: + build: + type: branch + spec: + branch: <+trigger.branch>