Bumps the github-actions-updates group with 15 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `3` | `4` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.0.2` | `4.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `3` | `4` | | [docker/login-action](https://github.com/docker/login-action) | `3.0.0` | `3.3.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `5.3.0` | `6.9.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `2` | `3` | | [actions/setup-go](https://github.com/actions/setup-go) | `2` | `5` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `3` | `4` | | [tj-actions/changed-files](https://github.com/tj-actions/changed-files) | `39.2.3` | `45.0.3` | | [mikepenz/action-junit-report](https://github.com/mikepenz/action-junit-report) | `3.7.7` | `4.3.1` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.1.2` | `2.4.0` | | [getsentry/action-release](https://github.com/getsentry/action-release) | `1.3.0` | `1.7.0` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.1.2` | `3.7.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.1.0` | `3.7.1` | | [actions/github-script](https://github.com/actions/github-script) | `6.4.1` | `7.0.1` | Updates `actions/checkout` from 3 to 4 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](https://github.com/actions/checkout/compare/v3...v4) Updates `actions/setup-node` from 4.0.2 to 4.1.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](60edb5dd54...39370e3970) Updates `actions/upload-artifact` from 3 to 4 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v3...v4) Updates `docker/login-action` from 3.0.0 to 3.3.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/v3...9780b0c442fbb1117ed29e0efdff1e18412f7567) Updates `docker/build-push-action` from 5.3.0 to 6.9.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](2cdde995de...4f58ea7922) Updates `github/codeql-action` from 2 to 3 - [Release notes](https://github.com/github/codeql-action/releases) - [Commits](https://github.com/github/codeql-action/compare/v2...v3) Updates `actions/setup-go` from 2 to 5 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/v2...v5) Updates `actions/download-artifact` from 3 to 4 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v3...v4) Updates `tj-actions/changed-files` from 39.2.3 to 45.0.3 - [Release notes](https://github.com/tj-actions/changed-files/releases) - [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md) - [Commits](95690f9ece...c3a1bb2c99) Updates `mikepenz/action-junit-report` from 3.7.7 to 4.3.1 - [Release notes](https://github.com/mikepenz/action-junit-report/releases) - [Commits](https://github.com/mikepenz/action-junit-report/compare/v3.7.7...db71d41eb79864e25ab0337e395c352e84523afe) Updates `ossf/scorecard-action` from 2.1.2 to 2.4.0 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](e38b1902ae...62b2cac7ed) Updates `getsentry/action-release` from 1.3.0 to 1.7.0 - [Release notes](https://github.com/getsentry/action-release/releases) - [Commits](85e0095193...e769183448) Updates `sigstore/cosign-installer` from 3.1.2 to 3.7.0 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](11086d2504...dc72c7d5c4) Updates `docker/setup-buildx-action` from 3.1.0 to 3.7.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](0d103c3126...c47758b77c) Updates `actions/github-script` from 6.4.1 to 7.0.1 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](d7906e4ad0...60a0d83039) --- updated-dependencies: - dependency-name: actions/checkout dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/setup-node dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: actions/upload-artifact dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: docker/build-push-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: github/codeql-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/setup-go dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: actions/download-artifact dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: tj-actions/changed-files dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: mikepenz/action-junit-report dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates - dependency-name: ossf/scorecard-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: getsentry/action-release dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: docker/setup-buildx-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-updates - dependency-name: actions/github-script dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
183 строки
7.4 KiB
YAML
183 строки
7.4 KiB
YAML
name: Server CI Artifacts
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows:
|
|
- "Server CI PR"
|
|
types:
|
|
- completed
|
|
|
|
env:
|
|
COSIGN_VERSION: 2.2.0
|
|
|
|
jobs:
|
|
## We only need the condition on the first job
|
|
## This will run only when a pull request is created with server changes
|
|
update-initial-status:
|
|
if: github.repository_owner == 'mattermost' && github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.conclusion == 'success'
|
|
runs-on: ubuntu-22.04
|
|
steps:
|
|
- uses: mattermost/actions/delivery/update-commit-status@fec7b836001c9380d4bfaf28d443945c103a098c
|
|
env:
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
with:
|
|
repository_full_name: ${{ github.repository }}
|
|
commit_sha: ${{ github.event.workflow_run.head_sha }}
|
|
context: Server CI/Artifacts Build
|
|
description: Artifacts upload and build for mattermost team platform
|
|
status: pending
|
|
|
|
upload-artifacts:
|
|
runs-on: ubuntu-22.04
|
|
needs:
|
|
- update-initial-status
|
|
steps:
|
|
- name: cd/configure-aws-credentials
|
|
uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4.0.2
|
|
with:
|
|
aws-region: us-east-1
|
|
aws-access-key-id: ${{ secrets.PR_BUILDS_BUCKET_AWS_ACCESS_KEY_ID }}
|
|
aws-secret-access-key: ${{ secrets.PR_BUILDS_BUCKET_AWS_SECRET_ACCESS_KEY }}
|
|
|
|
- name: cd/download-artifacts-from-PR-workflow
|
|
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
|
|
with:
|
|
run-id: ${{ github.event.workflow_run.id }}
|
|
github-token: ${{ github.token }}
|
|
name: server-dist-artifact
|
|
path: server/dist
|
|
|
|
- name: cd/generate-packages-file-list
|
|
working-directory: ./server/dist
|
|
run: |
|
|
echo "PACKAGES_FILE_LIST<<EOF" >> "${GITHUB_ENV}"
|
|
ls | grep -E "*.(tar.gz|zip)$" >> "${GITHUB_ENV}"
|
|
echo "EOF" >> "${GITHUB_ENV}"
|
|
|
|
- name: cd/upload-artifacts-to-s3
|
|
run: aws s3 sync server/dist/ s3://pr-builds.mattermost.com/mattermost/commit/${{ github.event.workflow_run.head_sha }}/ --cache-control no-cache --no-progress --acl public-read
|
|
|
|
- name: cd/generate-summary
|
|
run: |
|
|
echo "### Download links for Mattermost team package" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo " " >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Mattermost Repo SHA: \`${{ github.event.workflow_run.head_sha }}\`" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "|Download Link|" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "| --- |" >> "${GITHUB_STEP_SUMMARY}"
|
|
for package in ${PACKAGES_FILE_LIST}
|
|
do
|
|
echo "|[${package}](https://pr-builds.mattermost.com/mattermost/commit/${{ github.event.workflow_run.head_sha }}/${package})|" >> "${GITHUB_STEP_SUMMARY}"
|
|
done
|
|
|
|
build-docker:
|
|
runs-on: ubuntu-22.04
|
|
needs:
|
|
- upload-artifacts
|
|
outputs:
|
|
TAG: ${{ steps.set_tag.outputs.TAG }}
|
|
steps:
|
|
- name: cd/docker-login
|
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
|
with:
|
|
username: mattermostdev
|
|
password: ${{ secrets.DOCKERHUB_DEV_TOKEN }}
|
|
|
|
- name: cd/setup-cosign
|
|
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
|
|
with:
|
|
cosign-release: v${{ env.COSIGN_VERSION }}
|
|
|
|
- name: cd/download-artifacts-from-PR-workflow
|
|
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
|
|
with:
|
|
run-id: ${{ github.event.workflow_run.id }}
|
|
github-token: ${{ github.token }}
|
|
name: server-build-artifact
|
|
path: server/build/
|
|
|
|
- name: cd/setup-docker-buildx
|
|
uses: docker/setup-buildx-action@c47758b77c9736f4b2ef4073d4d51994fabfe349 # v3.7.1
|
|
|
|
- name: cd/set-docker-tag
|
|
id: set_tag
|
|
run: |
|
|
echo "TAG=$(echo '${{ github.event.workflow_run.head_sha }}' | cut -c1-7)" >> $GITHUB_OUTPUT
|
|
|
|
- name: cd/docker-build-and-push
|
|
id: docker
|
|
env:
|
|
MM_PACKAGE: https://pr-builds.mattermost.com/mattermost/commit/${{ github.event.workflow_run.head_sha }}/mattermost-team-linux-amd64.tar.gz
|
|
TAG: ${{ steps.set_tag.outputs.TAG }}
|
|
run: |
|
|
cd server/build
|
|
docker buildx build --no-cache --platform linux/amd64 --push --build-arg MM_PACKAGE=${MM_PACKAGE} -t mattermostdevelopment/mm-te-test:${TAG} -t mattermostdevelopment/mattermost-team-edition:${TAG} .
|
|
echo "DOCKERHUB_IMAGE_DIGEST=$(cosign triangulate mattermostdevelopment/mattermost-team-edition:${TAG} | cut -d: -f2 | sed 's/\.sig$//' | tr '-' ':')" >> "${GITHUB_OUTPUT}"
|
|
|
|
- name: cd/generate-summary
|
|
env:
|
|
TAG: ${{ steps.set_tag.outputs.TAG }}
|
|
run: |
|
|
echo "### Docker Image for Mattermost team package" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo " " >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Mattermost Repo SHA: \`${{ github.event.workflow_run.head_sha }}\`" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo " " >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Docker Image: \`mattermostdevelopment/mattermost-team-edition:${TAG}\`" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Image Digest: \`${{ steps.docker.outputs.DOCKERHUB_IMAGE_DIGEST }}\`" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Secure Image: \`mattermostdevelopment/mattermost-team-edition:${TAG}@${{ steps.docker.outputs.DOCKERHUB_IMAGE_DIGEST }}\`" >> "${GITHUB_STEP_SUMMARY}"
|
|
|
|
scan-docker-image:
|
|
runs-on: ubuntu-22.04
|
|
needs:
|
|
- build-docker
|
|
env:
|
|
POLICY: "DevOps Vulnerabilities Policy"
|
|
steps:
|
|
- name: cd/setup-wizcli
|
|
run: |
|
|
curl -o wizcli https://downloads.wiz.io/wizcli/latest/wizcli-linux-amd64
|
|
chmod +x wizcli
|
|
./wizcli auth --id "$WIZ_CLIENT_ID" --secret "$WIZ_CLIENT_SECRET"
|
|
env:
|
|
WIZ_CLIENT_ID: ${{ secrets.WIZ_DEVOPS_CLIENT_ID }}
|
|
WIZ_CLIENT_SECRET: ${{ secrets.WIZ_DEVOPS_CLIENT_SECRET }}
|
|
|
|
- name: cd/download-container-image
|
|
run: |
|
|
docker pull mattermostdevelopment/mattermost-team-edition:${{ needs.build-docker.outputs.TAG }}
|
|
|
|
- name: cd/scan-image
|
|
run: |
|
|
./wizcli docker scan --image mattermostdevelopment/mattermost-team-edition:${{ needs.build-docker.outputs.TAG }} --policy "$POLICY"
|
|
|
|
update-failure-final-status:
|
|
if: failure() || cancelled()
|
|
runs-on: ubuntu-22.04
|
|
needs:
|
|
- build-docker
|
|
steps:
|
|
- uses: mattermost/actions/delivery/update-commit-status@fec7b836001c9380d4bfaf28d443945c103a098c
|
|
env:
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
with:
|
|
repository_full_name: ${{ github.repository }}
|
|
commit_sha: ${{ github.event.workflow_run.head_sha }}
|
|
context: Server CI/Artifacts Build
|
|
description: Artifacts upload and build for mattermost team platform
|
|
status: failure
|
|
|
|
update-success-final-status:
|
|
if: success()
|
|
runs-on: ubuntu-22.04
|
|
needs:
|
|
- build-docker
|
|
steps:
|
|
- uses: mattermost/actions/delivery/update-commit-status@fec7b836001c9380d4bfaf28d443945c103a098c
|
|
env:
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
with:
|
|
repository_full_name: ${{ github.repository }}
|
|
commit_sha: ${{ github.event.workflow_run.head_sha }}
|
|
context: Server CI/Artifacts Build
|
|
description: Artifacts upload and build for mattermost team platform
|
|
status: success
|