Merge pull request #43 from idlab-discover/dependabot/go_modules/depe… #160
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: aibomgen-cli Go Build | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| build: | |
| permissions: | |
| contents: read | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| go-version: ["1.25.x"] | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v6 | |
| - name: Set up Go ${{ matrix.go-version }} | |
| uses: actions/setup-go@v6 | |
| with: | |
| go-version: ${{ matrix.go-version }} | |
| check-latest: true | |
| cache: true | |
| cache-dependency-path: | | |
| **/go.sum | |
| **/go.work.sum | |
| - name: Show Go env | |
| run: | | |
| go version | |
| go env GOMODCACHE GOCACHE GOOS GOARCH | |
| - name: Install dependencies | |
| run: go mod tidy | |
| - name: Run go vet | |
| run: go vet ./... | |
| - name: Run golangci-lint | |
| uses: golangci/golangci-lint-action@v9 | |
| with: | |
| version: v2.11 | |
| - name: Run tests (no coverage) | |
| if: ${{ matrix.go-version != '1.25.x' }} | |
| run: go test ./... | |
| - name: Run tests (with coverage) | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| run: go test ./... -coverprofile=coverage.out -covermode=atomic | |
| - name: Check coverage threshold | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| shell: bash | |
| env: | |
| COVERAGE_THRESHOLD: 0 | |
| run: | | |
| if [ ! -f coverage.out ]; then | |
| echo "No coverage report found"; exit 1 | |
| fi | |
| percent=$(go tool cover -func=coverage.out | awk '/total:/ {print $3}' | sed 's/%//') | |
| echo "Coverage: $percent%" | |
| int=${percent%.*} | |
| if [ "$int" -lt "$COVERAGE_THRESHOLD" ]; then | |
| echo "Coverage $percent% is below required ${COVERAGE_THRESHOLD}%"; exit 1 | |
| fi | |
| - name: Build | |
| run: | | |
| go build -o aibomgen-cli ./ | |
| chmod +x aibomgen-cli | |
| - name: Generate SBOM (Syft) | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| uses: anchore/sbom-action@v0 | |
| with: | |
| file: ./aibomgen-cli | |
| format: cyclonedx-json | |
| output-file: sbom-binary.json | |
| upload-artifact: false | |
| - name: Scan SBOM for vulnerabilities (Grype) | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| uses: anchore/scan-action@v7 | |
| with: | |
| sbom: sbom-binary.json | |
| output-format: cyclonedx-json | |
| output-file: sbom-binary-vulnerabilities.json | |
| fail-build: false | |
| - name: Scan SBOM for vulnerabilities (Grype) — table output | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| uses: anchore/scan-action@v7 | |
| with: | |
| sbom: sbom-binary.json | |
| output-format: table | |
| output-file: grype.table | |
| fail-build: false | |
| - name: Vulnerability summary (grype) | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| run: | | |
| set -eo pipefail | |
| if [ -f grype.table ] && [ -s grype.table ]; then | |
| head -n 50 grype.table >> "$GITHUB_STEP_SUMMARY" | |
| else | |
| echo "No results from grype" >> "$GITHUB_STEP_SUMMARY" | |
| fi | |
| - name: Upload vulnerability reports | |
| if: ${{ matrix.go-version == '1.25.x' && (success() || failure()) }} | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: vulnerability-reports | |
| path: | | |
| sbom-binary-vulnerabilities.json | |
| grype.table | |
| sbom-binary.json | |
| retention-days: 30 | |
| - name: Fail if vulnerabilities found | |
| if: ${{ matrix.go-version == '1.25.x' }} | |
| run: | | |
| if [ ! -f sbom-binary-vulnerabilities.json ]; then | |
| echo "vulnerabilities file not found"; exit 1 | |
| fi | |
| count=$(jq '.vulnerabilities | length' sbom-binary-vulnerabilities.json || echo 0) | |
| if [ "$count" -gt 0 ]; then | |
| echo "Found $count vulnerabilities in SBOM"; exit 1 | |
| fi | |