-
Notifications
You must be signed in to change notification settings - Fork 807
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Added "parrot" command, removed CodeQL action file in favor of built-…
…in advanced security bot
- Loading branch information
Showing
13 changed files
with
652 additions
and
435 deletions.
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,63 @@ | ||
# This workflow will build a golang project | ||
# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-go | ||
|
||
name: "Merlin Server Build & Test" | ||
|
||
on: | ||
push: | ||
pull_request: | ||
|
||
jobs: | ||
|
||
build: | ||
name: 'Build Job' | ||
runs-on: ubuntu-latest | ||
steps: | ||
- name: Checkout Repository | ||
id: checkout | ||
uses: actions/checkout@v3 | ||
|
||
- name: Set up Go | ||
uses: actions/setup-go@v4 | ||
with: | ||
go-version: '1.21' | ||
|
||
- name: 'Build Merlin Server' | ||
id: build | ||
run: 'make distro' | ||
|
||
- name: 'Test Merlin Server' | ||
id: test | ||
run: 'go test ./...' | ||
|
||
- name: GoVulnCheck | ||
id: govulncheck | ||
uses: golang/govulncheck-action@v1 | ||
with: | ||
go-version-input: '1.21' | ||
go-package: './...' | ||
|
||
- name: Gosec Security Scanner | ||
id: gosec | ||
uses: securego/gosec@master | ||
with: | ||
args: '-fmt sarif -out gosec.sarif ./...' | ||
|
||
- name: Upload Gosec SARIF file | ||
id: gosec_upload_sarif | ||
uses: github/codeql-action/upload-sarif@v2 | ||
with: | ||
sarif_file: gosec.sarif | ||
|
||
- name: Go Report Card - Install | ||
id: goreportcard_install | ||
working-directory: /tmp | ||
run: | | ||
git clone https://github.com/gojp/goreportcard.git | ||
cd goreportcard | ||
make install | ||
go install ./cmd/goreportcard-cli | ||
- name: Go Report Card - Run | ||
id: goreportcard_run | ||
run: 'goreportcard-cli -v' # This renames the files in the ./rpc directory to *.grc.bak causing builds to fail |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,105 @@ | ||
name: "Merlin Server Release" | ||
|
||
on: | ||
push: | ||
tags: | ||
- 'v*.*.*' | ||
|
||
defaults: | ||
run: | ||
working-directory: ~/ | ||
|
||
jobs: | ||
release: | ||
name: 'Release Job' | ||
runs-on: ubuntu-latest | ||
steps: | ||
- name: Checkout Merlin | ||
id: checkout_merlin | ||
uses: actions/checkout@v4 | ||
|
||
- name: Checkout Merlin-Agent | ||
id: checkout_merlin_agent | ||
uses: actions/checkout@v4 | ||
with: | ||
repository: 'Ne0nd0g/merlin-agent' | ||
path: 'merlin-agent' | ||
|
||
- name: Checkout Merlin-Agent-DLL | ||
id: checkout_merlin_agent_dll | ||
uses: actions/checkout@v4 | ||
with: | ||
repository: 'Ne0nd0g/merlin-agent-dll' | ||
path: 'merlin-agent-dll' | ||
|
||
- name: Checkout Merlin CLI | ||
id: checkout_merlin_cli | ||
uses: actions/checkout@v4 | ||
with: | ||
repository: 'Ne0nd0g/merlin-cli' | ||
path: 'merlin-cli' | ||
|
||
- name: Set up Go | ||
id: setup_go | ||
uses: actions/setup-go@v4 | ||
with: | ||
go-version: '1.21' | ||
|
||
# Need 7zip installed to package up the release | ||
- name: Install 7zip | ||
id: install_7zip | ||
run: apt-get install p7zip-full | ||
|
||
# Need MingGW installed to build the Agent DLL | ||
- name: Install MingGW | ||
id: install_mingw | ||
run: apt-get install -y -q mingw-w64 | ||
|
||
- name: Build Merlin Agents | ||
id: build_agents | ||
working-directory: merlin-agent | ||
run: | | ||
pwd | ||
make distro | ||
- name: Build Merlin Agent DLL | ||
id: build_agent_dll | ||
working-directory: merlin-agent-dll | ||
run: make default | ||
|
||
- name: Move Agents | ||
id: move_agents | ||
run: | | ||
mkdir -p data/bin | ||
cp ~/merlin-agent/merlinAgent-* ~/merlin/data/bin | ||
cp ~/merlin-agent-dll/merlinAgent.dll ~/merlin/data/bin | ||
- name: Build Merlin CLI | ||
id: build_cli | ||
working-directory: merlin-cli | ||
run: make all | ||
|
||
- name: Build Merlin Server | ||
id: build_server | ||
working-directory: merlin | ||
run: make distro | ||
|
||
- name: Package Release | ||
id: package_release | ||
working-directory: merlin | ||
run: | | ||
F="README.MD LICENSE data/modules docs data/README.MD data/agents/README.MD data/log/README.MD data/x509 data/src data/bin" | ||
7za a -pmerlin -mhe -mx=9 merlinServer-Linux-x64.7z $F merlinCLI-Linux-x64 merlinServer-Linux-x64 | ||
- name: Create Draft Release | ||
id: create_draft_release | ||
uses: ncipollo/release-action@v1 | ||
env: | ||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
with: | ||
tag: ${{ github.ref_name }} | ||
name: ${{ github.ref_name }} | ||
draft: true | ||
prerelease: false | ||
artifactErrorsFailBuild: true | ||
artifacts: '*.7z' |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.