name: "make" on: push: branches: - "main" pull_request: branches: - "main" jobs: release-snapshot: name: "release-snapshot" runs-on: "ubuntu-24.04" permissions: contents: "read" packages: "write" id-token: "write" security-events: "write" steps: - uses: "actions/checkout@v4" with: fetch-depth: 0 - uses: "actions/setup-go@v5" with: go-version: "1.25" - uses: "actions/setup-node@v4" with: node-version-file: ".nvmrc" - run: "npm ci" - uses: "docker/setup-qemu-action@v3" - uses: "docker/setup-buildx-action@v3" - uses: "sigstore/cosign-installer@v3" - uses: "anchore/sbom-action/download-syft@da167eac915b4e86f08b264dbdbc867b61be6f0c" # v0.20.5 - uses: "goreleaser/goreleaser-action@v6" with: distribution: "goreleaser" version: "~> v2" args: "release --clean --snapshot" env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - uses: "aquasecurity/trivy-action@0.28.0" with: image-ref: "ghcr.io/getprobo/probo:latest-amd64" format: "sarif" output: "trivy-results.sarif" exit-code: 1 ignore-unfixed: true vuln-type: "os,library" severity: "CRITICAL,HIGH" - name: Upload Trivy scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v4 with: sarif_file: "trivy-results.sarif" test: name: "test" runs-on: "ubuntu-22.04" permissions: contents: "read" steps: - uses: "actions/checkout@v4" - uses: "actions/setup-go@v5" with: go-version: "1.25" - uses: "actions/setup-node@v4" with: node-version-file: ".nvmrc" - run: "npm ci" - run: "make build" - run: "make test" - run: "make coverage-report" - name: "Upload coverage reports" uses: "actions/upload-artifact@v4" with: name: "coverage-reports" path: | coverage.out coverage.html retention-days: 30 - run: "make lint" - name: Generate SBOM uses: anchore/sbom-action@da167eac915b4e86f08b264dbdbc867b61be6f0c #v0.20.5 with: path: ./ format: cyclonedx-json output-file: sbom.json - name: Run vulnerability scan uses: anchore/scan-action@1638637db639e0ade3258b51db49a9a137574c3e #v6.5.1 with: path: ./ fail-build: true severity-cutoff: critical test-e2e: name: "test-e2e" runs-on: "ubuntu-22.04" permissions: contents: "read" services: postgres: image: "postgres:17.4" env: POSTGRES_USER: "postgres" POSTGRES_PASSWORD: "postgres" ports: - "5432:5432" options: >- --health-cmd "pg_isready -U postgres" --health-interval 10s --health-timeout 5s --health-retries 5 minio: image: "bitnami/minio:latest" env: MINIO_ROOT_USER: "probod" MINIO_ROOT_PASSWORD: "thisisnotasecret" MINIO_DEFAULT_BUCKETS: "probod-test" ports: - "9000:9000" options: >- --health-cmd "curl -f http://localhost:9000/minio/health/live || exit 1" --health-interval 10s --health-timeout 5s --health-retries 5 mailpit: image: "axllent/mailpit:latest" env: MP_DISABLE_VERSION_CHECK: "true" MP_VERBOSE: "false" MP_SMTP_AUTH_ACCEPT_ANY: "true" MP_SMTP_AUTH_ALLOW_INSECURE: "true" ports: - "1025:1025" chrome: image: "chromedp/headless-shell:140.0.7259.2" ports: - "9222:9222" pebble: image: "ghcr.io/letsencrypt/pebble:latest" env: PEBBLE_VA_NOSLEEP: "1" PEBBLE_WFE_NONCEREJECT: "0" PEBBLE_VA_ALWAYS_VALID: "1" ports: - "14000:14000" steps: - uses: "actions/checkout@v4" - uses: "actions/setup-go@v5" with: go-version: "1.25" - uses: "actions/setup-node@v4" with: node-version-file: ".nvmrc" - run: "npm ci" - name: "Setup PostgreSQL database" env: PGHOST: "localhost" PGUSER: "postgres" PGPASSWORD: "postgres" run: | psql -c "CREATE DATABASE probod_test;" - run: "make build" - name: "Run e2e tests" run: "make test-e2e"