Skip to content

Merge pull request #43 from idlab-discover/dependabot/go_modules/depe… #160

Merge pull request #43 from idlab-discover/dependabot/go_modules/depe…

Merge pull request #43 from idlab-discover/dependabot/go_modules/depe… #160

Workflow file for this run

name: aibomgen-cli Go Build
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
build:
permissions:
contents: read
runs-on: ubuntu-latest
strategy:
matrix:
go-version: ["1.25.x"]
steps:
- name: Checkout code
uses: actions/checkout@v6
- name: Set up Go ${{ matrix.go-version }}
uses: actions/setup-go@v6
with:
go-version: ${{ matrix.go-version }}
check-latest: true
cache: true
cache-dependency-path: |
**/go.sum
**/go.work.sum
- name: Show Go env
run: |
go version
go env GOMODCACHE GOCACHE GOOS GOARCH
- name: Install dependencies
run: go mod tidy
- name: Run go vet
run: go vet ./...
- name: Run golangci-lint
uses: golangci/golangci-lint-action@v9
with:
version: v2.11
- name: Run tests (no coverage)
if: ${{ matrix.go-version != '1.25.x' }}
run: go test ./...
- name: Run tests (with coverage)
if: ${{ matrix.go-version == '1.25.x' }}
run: go test ./... -coverprofile=coverage.out -covermode=atomic
- name: Check coverage threshold
if: ${{ matrix.go-version == '1.25.x' }}
shell: bash
env:
COVERAGE_THRESHOLD: 0
run: |
if [ ! -f coverage.out ]; then
echo "No coverage report found"; exit 1
fi
percent=$(go tool cover -func=coverage.out | awk '/total:/ {print $3}' | sed 's/%//')
echo "Coverage: $percent%"
int=${percent%.*}
if [ "$int" -lt "$COVERAGE_THRESHOLD" ]; then
echo "Coverage $percent% is below required ${COVERAGE_THRESHOLD}%"; exit 1
fi
- name: Build
run: |
go build -o aibomgen-cli ./
chmod +x aibomgen-cli
- name: Generate SBOM (Syft)
if: ${{ matrix.go-version == '1.25.x' }}
uses: anchore/sbom-action@v0
with:
file: ./aibomgen-cli
format: cyclonedx-json
output-file: sbom-binary.json
upload-artifact: false
- name: Scan SBOM for vulnerabilities (Grype)
if: ${{ matrix.go-version == '1.25.x' }}
uses: anchore/scan-action@v7
with:
sbom: sbom-binary.json
output-format: cyclonedx-json
output-file: sbom-binary-vulnerabilities.json
fail-build: false
- name: Scan SBOM for vulnerabilities (Grype) — table output
if: ${{ matrix.go-version == '1.25.x' }}
uses: anchore/scan-action@v7
with:
sbom: sbom-binary.json
output-format: table
output-file: grype.table
fail-build: false
- name: Vulnerability summary (grype)
if: ${{ matrix.go-version == '1.25.x' }}
run: |
set -eo pipefail
if [ -f grype.table ] && [ -s grype.table ]; then
head -n 50 grype.table >> "$GITHUB_STEP_SUMMARY"
else
echo "No results from grype" >> "$GITHUB_STEP_SUMMARY"
fi
- name: Upload vulnerability reports
if: ${{ matrix.go-version == '1.25.x' && (success() || failure()) }}
uses: actions/upload-artifact@v7
with:
name: vulnerability-reports
path: |
sbom-binary-vulnerabilities.json
grype.table
sbom-binary.json
retention-days: 30
- name: Fail if vulnerabilities found
if: ${{ matrix.go-version == '1.25.x' }}
run: |
if [ ! -f sbom-binary-vulnerabilities.json ]; then
echo "vulnerabilities file not found"; exit 1
fi
count=$(jq '.vulnerabilities | length' sbom-binary-vulnerabilities.json || echo 0)
if [ "$count" -gt 0 ]; then
echo "Found $count vulnerabilities in SBOM"; exit 1
fi