mirror of
https://github.com/cisagov/log4j-affected-db.git
synced 2024-11-23 00:50:48 +00:00
8797e110d3
This changes from using an environment variable to using a step output to store the Go version that is installed. This mirrors changes made to the other program versions and how they're stored.
105 lines
4 KiB
YAML
105 lines
4 KiB
YAML
---
|
|
name: build
|
|
|
|
on:
|
|
push:
|
|
pull_request:
|
|
repository_dispatch:
|
|
types: [apb]
|
|
|
|
env:
|
|
CURL_CACHE_DIR: ~/.cache/curl
|
|
PIP_CACHE_DIR: ~/.cache/pip
|
|
PRE_COMMIT_CACHE_DIR: ~/.cache/pre-commit
|
|
RUN_TMATE: ${{ secrets.RUN_TMATE }}
|
|
|
|
jobs:
|
|
lint:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- id: setup-env
|
|
uses: cisagov/setup-env-github-action@develop
|
|
- uses: actions/checkout@v2
|
|
- id: setup-python
|
|
uses: actions/setup-python@v2
|
|
with:
|
|
python-version: 3.9
|
|
# We need the Go version and Go cache location for the actions/cache step,
|
|
# so the Go installation must happen before that.
|
|
- uses: actions/setup-go@v2
|
|
with:
|
|
go-version: '1.16'
|
|
- name: Store installed Go version
|
|
id: go-version
|
|
run: |
|
|
echo "::set-output name=version::"\
|
|
"$(go version | sed 's/^go version go\([0-9.]\+\) .*/\1/')"
|
|
- name: Lookup Go cache directory
|
|
id: go-cache
|
|
run: |
|
|
echo "::set-output name=dir::$(go env GOCACHE)"
|
|
- uses: actions/cache@v2
|
|
env:
|
|
BASE_CACHE_KEY: "${{ github.job }}-${{ runner.os }}-\
|
|
py${{ steps.setup-python.outputs.python-version }}-\
|
|
go${{ steps.go-version.outputs.version }}-\
|
|
packer${{ steps.setup-env.outputs.packer-version }}-\
|
|
tf${{ steps.setup-env.outputs.terraform-version }}-"
|
|
with:
|
|
# Note that the .terraform directory IS NOT included in the
|
|
# cache because if we were caching, then we would need to use
|
|
# the `-upgrade=true` option. This option blindly pulls down the
|
|
# latest modules and providers instead of checking to see if an
|
|
# update is required. That behavior defeats the benefits of caching.
|
|
# so there is no point in doing it for the .terraform directory.
|
|
path: |
|
|
${{ env.PIP_CACHE_DIR }}
|
|
${{ env.PRE_COMMIT_CACHE_DIR }}
|
|
${{ env.CURL_CACHE_DIR }}
|
|
${{ steps.go-cache.outputs.dir }}
|
|
key: "${{ env.BASE_CACHE_KEY }}\
|
|
${{ hashFiles('**/requirements-test.txt') }}-\
|
|
${{ hashFiles('**/requirements.txt') }}-\
|
|
${{ hashFiles('**/.pre-commit-config.yaml') }}"
|
|
restore-keys: |
|
|
${{ env.BASE_CACHE_KEY }}
|
|
- name: Setup curl cache
|
|
run: mkdir -p ${{ env.CURL_CACHE_DIR }}
|
|
- name: Install Packer
|
|
env:
|
|
PACKER_VERSION: ${{ steps.setup-env.outputs.packer-version }}
|
|
run: |
|
|
PACKER_ZIP="packer_${PACKER_VERSION}_linux_amd64.zip"
|
|
curl --output ${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}" \
|
|
--time-cond ${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}" \
|
|
--location \
|
|
"https://releases.hashicorp.com/packer/${PACKER_VERSION}/${PACKER_ZIP}"
|
|
sudo unzip -d /opt/packer \
|
|
${{ env.CURL_CACHE_DIR }}/"${PACKER_ZIP}"
|
|
sudo mv /usr/local/bin/packer /usr/local/bin/packer-default
|
|
sudo ln -s /opt/packer/packer /usr/local/bin/packer
|
|
- uses: hashicorp/setup-terraform@v1
|
|
with:
|
|
terraform_version: ${{ steps.setup-env.outputs.terraform-version }}
|
|
- name: Install shfmt
|
|
env:
|
|
PACKAGE_URL: mvdan.cc/sh/v3/cmd/shfmt
|
|
PACKAGE_VERSION: ${{ steps.setup-env.outputs.shfmt-version }}
|
|
run: go install ${PACKAGE_URL}@${PACKAGE_VERSION}
|
|
- name: Install Terraform-docs
|
|
env:
|
|
PACKAGE_URL: github.com/terraform-docs/terraform-docs
|
|
PACKAGE_VERSION: ${{ steps.setup-env.outputs.terraform-docs-version }}
|
|
run: go install ${PACKAGE_URL}@${PACKAGE_VERSION}
|
|
- name: Install dependencies
|
|
run: |
|
|
python -m pip install --upgrade pip
|
|
pip install --upgrade --requirement requirements-test.txt
|
|
- name: Set up pre-commit hook environments
|
|
run: pre-commit install-hooks
|
|
- name: Run pre-commit on all files
|
|
run: pre-commit run --all-files
|
|
- name: Setup tmate debug session
|
|
uses: mxschmitt/action-tmate@v3
|
|
if: env.RUN_TMATE
|