-
Notifications
You must be signed in to change notification settings - Fork 509
112 lines (89 loc) · 3.82 KB
/
gobuild.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
name: build
on:
push:
pull_request:
schedule:
- cron: 0 23 * * *
jobs:
validate:
runs-on: ubuntu-latest
env:
GO111MODULE: on
GOPATH: /home/runner/work/terrascan
GOBIN: /home/runner/work/terrascan/bin
GO_VERSION: 1.19
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID_TEST }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY_TEST }}
AWS_REGION: ${{ secrets.AWS_REGION_TEST }}
AZURE_AUTH_TEST_SECRET: ${{ secrets.AZURE_AUTH_TEST_KEY }}
GOOGLE_APPLICATION_CREDENTIALS_TEST_SECRET: ${{ secrets.GOOGLE_APPLICATION_CREDENTIALS_TEST_KEY }}
steps:
- name: Checkout Terrascan
uses: actions/checkout@v3
- name: Run test.sh
run: |
chmod +x test.sh
./test.sh
- name: Test
run: |
ls
cat test.txt
- name: Run scan
run: |
image_tag=$(<test.txt)
echo $image_tag
echo "{\"APPID\":\"test\", \"IMAGE\":\"docker-terrascan-local.artifactory.eng.tenable.com/terrascan:${image_tag}\""
docker run -e JKN_USERNAME=${{ secrets.JKN_USERNAME }} -e JKN_PASSWORD=${{ secrets.JKN_PASSWORD }} -t docker-terrascan-local.artifactory.eng.tenable.com/tenb-cb:1.0.10.DEV231011191849-J-EPRT-TENB-CB-TENB-CB-CICD-5797-10 jobs execute-job --credential-mode env -n teams-deleng-terraform -p deleng-terraform/Scratch/dockerhub-tester -d '{"APPID":"test", "IMAGE":"docker-terrascan-local.artifactory.eng.tenable.com/terrascan:\"$image_tag\"}}", "TARGETS": "tenable/terrascan:test,tenable/was-scanner:latest", "MULTIARCH":"true"}' --cloudflare-access-secret ${{ secrets.CF_ACCESS_TOKEN }}:${{ secrets.CF_SECRET }}
- name: Setup Go
uses: actions/setup-go@v4
with:
go-version: ${{ env.GO_VERSION }}
- name: Install golint
run: go install golang.org/x/lint/golint@latest
- name: Build Terrascan docker image
run: make docker-build
#- name: Go validations
# run: make validate
- name: Build Terrascan
run: make build
#- name: Run unit tests
# run: make unit-tests
#- name: install kind
# run: make install-kind
#- name: Run e2e tests
# run: make e2e-tests
#- name: Run e2e vulnerability tests
# if: ${{ (github.event_name == 'push'|| github.event_name == 'schedule') && github.actor != 'dependabot[bot]' }}
# run: make e2e-vulnerability-tests
#- name: Upload coverage to Codecov
# uses: codecov/codecov-action@v1
# push image to Docker Hub
push:
# Ensure "validate" job passes before pushing image.
needs: validate
runs-on: ubuntu-latest
if: github.event_name == 'push' #&& github.ref == 'refs/heads/master'
steps:
- name: Checkout Terrascan
uses: actions/checkout@v3
- uses: docker/setup-qemu-action@v2
- name: Login to Artifactory
run: docker login --username svc_terrascan --password ${{ secrets.ARTIFACTORY_API_TOKEN }} https://docker-terrascan-local.artifactory.eng.tenable.com
- name: Pull Image
run: docker pull docker-terrascan-local.artifactory.eng.tenable.com/tenb-cb:1.0.10.DEV231011191849-J-EPRT-TENB-CB-TENB-CB-CICD-5797-10
- name: Build latest docker image
run: make docker-build-push-latest
env:
MULTIPLATFORM: true
- name: Read File and Set as Variable
id: read-file
run: |
file_content=$(<dockerhub-image-label.txt)
echo "::set-output name=file_content::$file_content"
- name: Read File and Set as Environment Variable
run: |
file_content=$(cat dockerhub-image-label.txt)
echo "FILE_CONTENT1=$file_content" >> $GITHUB_ENV
- name: Use Environment Variable
run: |
echo "Content of FILE_CONTENT is $FILE_CONTENT"