From fee2031a62f3d901d57d997248237481b39ba40d Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Mon, 14 Jul 2025 11:34:48 +0200 Subject: [PATCH] Fix main workflow Signed-off-by: Bryan Frimin --- .github/workflows/make.yaml | 46 ++++++++++++++++++++++++------------- 1 file changed, 30 insertions(+), 16 deletions(-) diff --git a/.github/workflows/make.yaml b/.github/workflows/make.yaml index bcd605d0b..9ff02606e 100644 --- a/.github/workflows/make.yaml +++ b/.github/workflows/make.yaml @@ -3,48 +3,62 @@ on: push: branches: - "main" - tags: - - "v*" pull_request: branches: - "main" jobs: - docker-build: - name: "docker-build" + release-snapshot: + name: "release-snapshot" runs-on: "ubuntu-24.04" permissions: contents: "read" packages: "write" - env: - DOCKER_BUILD_FLAGS: "--push" - DOCKER_TAG_NAME: ${{ startsWith(github.ref, 'refs/tags/') && github.ref_name || 'latest' }} + id-token: "write" steps: - uses: "actions/checkout@v4" - - uses: "docker/setup-qemu-action@v2" - - uses: "docker/setup-buildx-action@v2" - - uses: "docker/login-action@v2" + with: + fetch-depth: 0 + - uses: "actions/setup-go@v5" + with: + go-version: stable + - uses: "actions/setup-node@v4" + with: + node-version: 22 + - run: "npm ci" + - uses: "docker/setup-qemu-action@v3" + - uses: "docker/setup-buildx-action@v3" + - uses: "docker/login-action@v3" with: registry: "ghcr.io" username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - - run: "make docker-build" - + - uses: "sigstore/cosign-installer@v3" + - uses: "anchore/sbom-action/download-syft@v0" + - uses: "goreleaser/goreleaser-action@v6" + with: + distribution: "goreleaser" + version: "~> v2" + args: "release --clean ${{ github.event_name == 'pull_request' && '--snapshot' || '' }}" + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + trivy-scan: name: "trivy-scan" - needs: - - "docker-build" + needs: + - "release-snapshot" runs-on: "ubuntu-22.04" + # Only run security scan for main branch (not for PR snapshots since they aren't pushed) + if: github.event_name == 'push' && github.ref == 'refs/heads/main' permissions: contents: "read" packages: "read" env: - DOCKER_TAG_NAME: ${{ startsWith(github.ref, 'refs/tags/') && github.ref_name || 'latest' }} TRIVY_DISABLE_VEX_NOTICE: true steps: - uses: "aquasecurity/trivy-action@0.28.0" with: - image-ref: 'ghcr.io/getprobo/probo:${{ env.DOCKER_TAG_NAME }}' + image-ref: "ghcr.io/getprobo/probo:latest" format: "table" exit-code: 1 ignore-unfixed: true