Update GitHub workflows with various improvements (#1028)

Updated DB images in tests to align with the PROD setup
Try to upload coverage only if tests were executed (passed or failed) - not skipped or canceled
Added ESLint execution after UI tests with results exported to artifact
Shifted scheduled run time from 00 minutes according to GitHub recommendations, as the 00 minutes of each hour is the busiest time
Dynamically extract a list of langs from the repo to use them for CodeQL analysis instead of hardcoded ones
Updated versions of several outdated actions
Added the Autobuild step before CodeQL analysis for GO
Added the Anchore dependency scan job, reporting to the Security tab. I can add steps to manage PR comments with the results, but I need a token to be provided by @viktorstrate
Added the Hadolint Dockerfile scan job, reporting to the Security tab. I can add steps to manage PR comments with the results, but I need a token to be provided by @viktorstrate
Implemented weekly rebuild of images for the latest commit in the master branch and the latest released tag. It will recreate images with the recent base image and 3rd-party dependencies even if there were no new pushes for a long time
Added the Dockle container analysis job to be run on master and tag and validate just pushed images, reporting to the Security tab
Added golangci-lint config to the /api folder, as a starting point and for local usage
Added 2 weekly jobs for Dependabot:
-- Maintain dependencies for GitHub Actions
-- Maintain dependencies for Dockerfile

---------

Co-authored-by: Konstantin Koval
This commit is contained in:
Kostiantyn
2024-10-01 15:50:44 +03:00
committed by GitHub
parent f861c97b49
commit dee3a151e9
8 changed files with 723 additions and 30 deletions

15
.github/dependabot.yml vendored Normal file
View File

@@ -0,0 +1,15 @@
version: 2
updates:
# Maintain dependencies for GitHub Actions
- package-ecosystem: "github-actions"
directory: "/.github/workflows"
schedule:
interval: "weekly"
# Maintain dependencies for Dockerfile
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "weekly"
ignore:
- dependency-name: "node"

View File

@@ -1,12 +1,15 @@
name: Docker builds
on:
pull_request:
branches: [master]
push:
branches: [master]
tags:
- v*
pull_request:
branches: [master]
schedule:
# At 01:18 every Thursday. Details in https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule
- cron: '18 1 * * 4'
env:
IS_PUSHING_IMAGES: ${{ github.event_name != 'pull_request' && github.repository == 'photoview/photoview' }}
@@ -16,14 +19,62 @@ env:
PLATFORMS: linux/amd64,linux/arm64,linux/arm/v7
jobs:
build:
name: Build Docker Image
prepare:
name: Prepare the Matrix
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Prepare the Matrix
id: prepare_matrix
shell: bash
run: |
case ${{ github.event_name }} in
pull_request)
echo 'tags=[{"tag": "", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
;;
push)
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
;;
schedule)
git fetch --all
TAG=$(git describe --tags --abbrev=0 || exit 0)
if [ -z "$TAG" ]; then
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
else
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}, {"tag": "$TAG", "ref": "$(git show-ref --tags -d | grep "/$TAG$" | cut -d ' ' -f 2)"}]' >> $GITHUB_OUTPUT
fi
;;
*)
echo "Run for '${{ github.event_name }}' is not expected"
echo 'tags=[{"tag": "${{ github.ref_name }}", "ref": "${{ github.ref }}"}]' >> $GITHUB_OUTPUT
;;
esac
outputs:
tags: ${{ steps.prepare_matrix.outputs.tags }}
build:
name: Build Docker Image
runs-on: ubuntu-latest
needs: prepare
strategy:
fail-fast: false
matrix:
tags: ${{ fromJson(needs.prepare.outputs.tags) }}
steps:
- name: Delete huge unnecessary tools folder
run: rm -rf /opt/hostedtoolcache
- name: Checkout ${{ matrix.tags.ref }}
uses: actions/checkout@v4
with:
ref: ${{ matrix.tags.ref }}
- name: Fetch branches
run: git fetch --all
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
with:
@@ -60,16 +111,59 @@ jobs:
uses: docker/build-push-action@v6
with:
context: .
sbom: true
provenance: mode=max
platforms: ${{ env.PLATFORMS }}
pull: true
push: ${{ env.IS_PUSHING_IMAGES }}
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.docker_meta.outputs.labels }}
annotations: ${{ steps.docker_meta.outputs.annotations }}
cache-from: type=gha
cache-to: type=gha,mode=max
sbom: true
provenance: mode=max
annotations: ${{ steps.docker_meta.outputs.annotations }}
build-args: |
VERSION=${{ github.ref_name }}
COMMIT_SHA=${{ github.sha }}
dockle:
name: Dockle Container Analysis
runs-on: ubuntu-latest
needs:
- prepare
- build
strategy:
fail-fast: false
matrix:
tags: ${{ fromJson(needs.prepare.outputs.tags) }}
if: ${{ github.event_name != 'pull_request' && github.repository == 'photoview/photoview' }}
steps:
# Makes sure your .dockleignore file is available to the next step
- name: Checkout ${{ matrix.tags.ref }}
uses: actions/checkout@v4
with:
ref: ${{ matrix.tags.ref }}
- name: Docker Login
uses: docker/login-action@v3
with:
username: ${{ env.DOCKER_USERNAME }}
password: ${{ env.DOCKER_PASSWORD }}
- name: Run Dockle for '${{ env.DOCKER_IMAGE }}:${{ matrix.tags.tag }}'
id: dockle
if: ${{ matrix.tags.tag != '' }}
continue-on-error: true
uses: erzz/dockle-action@v1
with:
image: '${{ env.DOCKER_IMAGE }}:${{ matrix.tags.tag }}'
report-name: dockle-results-${{ matrix.tags.tag }}
report-format: sarif
failure-threshold: fatal
exit-code: 1
timeout: 5m
- name: Upload SARIF file
if: ${{ steps.dockle.conclusion == 'success' }}
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: dockle-results-${{ matrix.tags.tag }}.sarif

View File

@@ -7,34 +7,163 @@ on:
# The branches below must be a subset of the branches above
branches: [master]
schedule:
- cron: '0 1 * * 4'
# At 01:37 every Thursday. Details in https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule
- cron: '37 1 * * 4'
jobs:
analyze:
name: Analyze
if: github.repository == 'photoview/photoview'
runs-on: ubuntu-20.04
# strategy:
# fail-fast: false
# matrix:
# Override automatic language detection by changing the below list
# Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
# language: ['go', 'javascript']
# Learn more...
# https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection
create-matrix:
runs-on: ubuntu-latest
steps:
- name: Get languages from repo
id: set-matrix
uses: advanced-security/set-codeql-language-matrix@v1
with:
access-token: ${{ github.token }}
endpoint: ${{ github.event.repository.languages_url }}
outputs:
matrix: ${{ steps.set-matrix.outputs.languages }}
code-ql:
name: CodeQL
needs: create-matrix
if: ${{ needs.create-matrix.outputs.matrix != '[]' && github.repository == 'photoview/photoview' }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
language: ${{ fromJSON(needs.create-matrix.outputs.matrix) }}
steps:
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v4
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
uses: github/codeql-action/init@v3
with:
languages: go, javascript
languages: ${{ matrix.language }}
# Run further tests
queries: security-extended, security-and-quality
debug: true
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
- name: Autobuild
uses: github/codeql-action/autobuild@v3
with:
working-directory: ${{ ( matrix.language == 'go' && './api' ) || ( matrix.language == 'javascript' && './ui' ) || '.' }}
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
uses: github/codeql-action/analyze@v3
with:
category: "/language:${{ matrix.language }}"
anchore:
name: Anchore scan code dependencies
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Generate report
id: scan
uses: anchore/scan-action@v4
continue-on-error: true
with:
path: "."
fail-build: false
add-cpes-if-none: true
- name: Upload report
uses: github/codeql-action/upload-sarif@v3
if: ${{ steps.scan.conclusion == 'success' }}
with:
sarif_file: ${{ steps.scan.outputs.sarif }}
- name: Scan PR source code
id: scan-fixed
uses: anchore/scan-action@v4
if: always() && github.event_name == 'pull_request'
continue-on-error: true
with:
path: "."
fail-build: false
add-cpes-if-none: true
output-format: json
severity-cutoff: high
only-fixed: true
- name: Prepare JSON
if: ${{ steps.scan-fixed.conclusion == 'success' && github.event_name == 'pull_request' }}
run: |
jq '{
"|": .matches | map({
"language": .artifact.language,
"id": .vulnerability.id,
"severity": .vulnerability.severity,
"name": .artifact.name,
"version": .artifact.version,
"fix-versions": .vulnerability.fix.versions[0],
"path": .artifact.locations[0].path,
"description": .vulnerability.description
})
}' ${{ steps.scan-fixed.outputs.json }} > vulns.json
cat vulns.json | jq
- name: Anchore vulns artifact
id: anchore-artifact
uses: actions/upload-artifact@v4
with:
name: Anchore-vulns-report
path: ./vulns.json
if-no-files-found: warn
compression-level: 9
overwrite: true
hadolint:
name: Hadolint Dockerfile
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Lint Dockerfile
id: lint
uses: hadolint/hadolint-action@v3.1.0
continue-on-error: true
with:
dockerfile: Dockerfile
config: ${{ github.workspace }}/.hadolint.yaml
output-file: hadolint.txt
format: tty
failure-threshold: error
- name: Output results
if: ${{ steps.lint.conclusion == 'success' }}
run: |
cat ./hadolint.txt || echo ${HADOLINT_RESULTS}
- name: Hadolint artifact
id: hadolint-artifact
uses: actions/upload-artifact@v4
with:
name: hadolint-report
path: ./hadolint.txt
if-no-files-found: warn
compression-level: 9
overwrite: true
- name: Lint Dockerfile (sarif)
uses: hadolint/hadolint-action@v3.1.0
id: lint-report
continue-on-error: true
with:
dockerfile: Dockerfile
config: ${{ github.workspace }}/.hadolint.yaml
output-file: hadolint.sarif
format: sarif
failure-threshold: ignore
- name: Upload report
uses: github/codeql-action/upload-sarif@v3
if: ${{ steps.lint-report.conclusion == 'success' }}
with:
sarif_file: hadolint.sarif

View File

@@ -61,9 +61,9 @@ jobs:
push: ${{ env.IS_PUSHING_IMAGES }}
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.docker_meta.outputs.labels }}
annotations: ${{ steps.docker_meta.outputs.annotations }}
cache-from: ${{ ( env.IS_CACHING == 'true' && 'type=gha' ) || '' }}
cache-to: ${{ ( env.IS_CACHING == 'true' && 'type=gha,mode=max' ) || '' }}
no-cache: ${{ env.IS_CACHING != 'true' }}
sbom: true
provenance: mode=max
annotations: ${{ steps.docker_meta.outputs.annotations }}

View File

@@ -17,14 +17,15 @@ jobs:
services:
mariadb:
image: mariadb:10.5
image: mariadb:lts
env:
MYSQL_DATABASE: photoview_test
MYSQL_USER: photoview
MYSQL_PASSWORD: photosecret
MYSQL_RANDOM_ROOT_PASSWORD: yes
# https://github.com/MariaDB/mariadb-docker/issues/497
options: >-
--health-cmd="mysqladmin ping"
--health-cmd="mariadb-admin ping"
--health-interval=10s
--health-timeout=5s
--health-retries=5
@@ -32,7 +33,7 @@ jobs:
- 3306:3306
postgres:
image: postgres:13.2
image: postgres:16-alpine
env:
POSTGRES_USER: photoview
POSTGRES_PASSWORD: photosecret
@@ -64,6 +65,8 @@ jobs:
cache-to: type=gha,mode=max
- name: Test
id: test
continue-on-error: true
run: |
docker run --name test --network host \
-e PHOTOVIEW_DATABASE_DRIVER=${{ matrix.database }} \
@@ -76,6 +79,7 @@ jobs:
- name: Upload coverage
uses: codecov/codecov-action@v4
if: ${{ steps.test.conclusion == 'success' }}
with:
flags: api-${{ matrix.database }}
@@ -102,11 +106,33 @@ jobs:
cache-to: type=gha,mode=max
- name: Test
id: test
continue-on-error: true
run: |
docker run --name test photoview/ui npm run test:ci
docker cp test:/app/ui/coverage ./ui/
- name: Upload coverage
uses: codecov/codecov-action@v4
if: ${{ steps.test.conclusion == 'success' }}
with:
flags: ui
- name: Run ESLint
working-directory: ui
run: |
npm run lint:ci || true
echo "--------------------------"
echo "ESLint execution results :"
echo "--------------------------"
cat ./eslint-report.txt || echo "ESLint report file not found."
- name: ESLint artifact
id: eslint-artifact
uses: actions/upload-artifact@v4
with:
name: ESLint-report
path: ./ui/eslint-report.txt
if-no-files-found: warn
compression-level: 9
overwrite: true