From c05666673efc0a73e56c94d4745425fa41d7211b Mon Sep 17 00:00:00 2001 From: Mattia Roccoberton Date: Thu, 13 May 2021 22:24:14 +0200 Subject: [PATCH] Update GitHub Actions --- .github/workflows/brakeman-analysis.yml | 44 ------------------------- .github/workflows/specs.yml | 26 +++++++++++++++ 2 files changed, 26 insertions(+), 44 deletions(-) delete mode 100644 .github/workflows/brakeman-analysis.yml create mode 100644 .github/workflows/specs.yml diff --git a/.github/workflows/brakeman-analysis.yml b/.github/workflows/brakeman-analysis.yml deleted file mode 100644 index 4b8f33e..0000000 --- a/.github/workflows/brakeman-analysis.yml +++ /dev/null @@ -1,44 +0,0 @@ -# This workflow integrates Brakeman with GitHub's Code Scanning feature -# Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications - -name: Brakeman Scan - -# This section configures the trigger for the workflow. Feel free to customize depending on your convention -on: - push: - branches: [ "master", "main" ] - pull_request: - branches: [ "master", "main" ] - -jobs: - brakeman-scan: - name: Brakeman Scan - runs-on: ubuntu-latest - steps: - # Checkout the repository to the GitHub Actions runner - - name: Checkout - uses: actions/checkout@v2 - - # Customize the ruby version depending on your needs - - name: Setup Ruby - uses: actions/setup-ruby@v1 - with: - ruby-version: '2.7' - - - name: Setup Brakeman - env: - BRAKEMAN_VERSION: '4.10' # SARIF support is provided in Brakeman version 4.10+ - run: | - gem install brakeman --version $BRAKEMAN_VERSION - - # Execute Brakeman CLI and generate a SARIF output with the security issues identified during the analysis - - name: Scan - continue-on-error: true - run: | - brakeman -f sarif -o output.sarif.json . - - # Upload the SARIF file generated in the previous step - - name: Upload SARIF - uses: github/codeql-action/upload-sarif@v1 - with: - sarif_file: output.sarif.json diff --git a/.github/workflows/specs.yml b/.github/workflows/specs.yml new file mode 100644 index 0000000..2eab4dc --- /dev/null +++ b/.github/workflows/specs.yml @@ -0,0 +1,26 @@ +name: Specs + +on: + push: + branches: [master] + pull_request: + branches: [master] + +jobs: + specs: + runs-on: ubuntu-latest + + strategy: + matrix: + ruby: ['2.5', '2.6', '2.7'] + + steps: + - name: Checkout + uses: actions/checkout@v2 + - name: Set up Ruby + uses: ruby/setup-ruby@v1 + with: + ruby-version: ${{ matrix.ruby }} + bundler-cache: true # runs 'bundle install' and caches installed gems automatically + - name: Run tests + run: bundle exec rake