* Fix GitHub commit passing, UI build and cache for different purposes
* a logging for transparency and easy debug
* Fix var expanding with quotes and add intermediate verification commands
* split verification commands
* fix joining commands
* Ecplicitly pull latest deps image
* properly set arg default values and try to fix preparation step
* another try to build the image with the correct deps tag
* Revert the dynamic deps tag discovery, as it doesn't work and the actual `latest` image is pulled implicitly anyway
* Final optimizations
* "NoCommit" placeholder, indent fix, var rename
---------
Co-authored-by: Konstantin Koval
* Fix the local build of the dependencies image, including the debug image instructions
* Make the deps image easily runnable
* improve readme
* Better caching strategy
* make dependency from IM to libs build stages
* fix missing folder error
* Hopefully, final solution
---------
Co-authored-by: Konstantin Koval
* Initial implementation
* Multiple fixes and improvemens
* Better `curl` retries timing
* Remove unused `TARGETOS` and `TARGETVARIANT` vars; add the version fetch fallback code to the build scripts
* Move the fallback code before the var usage
* Use double braces to make the code compatible with the `set -u`
---------
Co-authored-by: Konstantin Koval
* Try to fix the incorrect tag processing
* more debug code
* try with context=git
* hopefully, final debug
* the final commit with no debug code
---------
Co-authored-by: Konstantin Koval
* test putting '"' to make the resulting JSON correct
* revert the testing code and move the fixed line to its final location
---------
Co-authored-by: Konstantin Koval
* try to fix by removing ''
* add source data for the debug
* Remove debug code
* Move the event logging before the `case`
---------
Co-authored-by: Konstantin Koval
* Set $NODE_ENV according to the image purpose during Docker build
* Move `husky` from dev-deps to prod-deps, as it is used during prod `npm ci`
---------
Co-authored-by: Konstantin Koval <kkb@ukr.net>
Updated DB images in tests to align with the PROD setup
Try to upload coverage only if tests were executed (passed or failed) - not skipped or canceled
Added ESLint execution after UI tests with results exported to artifact
Shifted scheduled run time from 00 minutes according to GitHub recommendations, as the 00 minutes of each hour is the busiest time
Dynamically extract a list of langs from the repo to use them for CodeQL analysis instead of hardcoded ones
Updated versions of several outdated actions
Added the Autobuild step before CodeQL analysis for GO
Added the Anchore dependency scan job, reporting to the Security tab. I can add steps to manage PR comments with the results, but I need a token to be provided by @viktorstrate
Added the Hadolint Dockerfile scan job, reporting to the Security tab. I can add steps to manage PR comments with the results, but I need a token to be provided by @viktorstrate
Implemented weekly rebuild of images for the latest commit in the master branch and the latest released tag. It will recreate images with the recent base image and 3rd-party dependencies even if there were no new pushes for a long time
Added the Dockle container analysis job to be run on master and tag and validate just pushed images, reporting to the Security tab
Added golangci-lint config to the /api folder, as a starting point and for local usage
Added 2 weekly jobs for Dependabot:
-- Maintain dependencies for GitHub Actions
-- Maintain dependencies for Dockerfile
---------
Co-authored-by: Konstantin Koval