Merge pull request #41 from openshift-bot/art-consistency-openshift-4… #10
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Build, Test, and Lint | |
on: | |
push: | |
branches: | |
- main | |
- 'release-*' | |
pull_request_target: | |
jobs: | |
build-container: | |
runs-on: ubuntu-latest | |
env: | |
EXPORT_RESULT: true | |
steps: | |
- name: Checkout | |
uses: actions/checkout@v4 | |
with: | |
ref: "${{ github.event.pull_request.head.sha }}" | |
- name: Install devbox | |
uses: jetify-com/devbox-install-action@v0.11.0 | |
with: | |
enable-cache: "true" | |
- uses: actions/cache@v4 | |
with: | |
path: | | |
~/.cache/golangci-lint | |
~/.cache/go-build | |
~/go/pkg/mod | |
key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }} | |
restore-keys: | | |
${{ runner.os }}-go- | |
- name: Test build | |
run: devbox run -- make build | |
- name: Run unit tests | |
run: devbox run -- make unit-test | |
# gocov-xml expects things to be properly placed under go path. | |
# GHA clones into /home/runner/work/repository so we create | |
# the directory under the right path and link it | |
- run: mkdir -p /home/runner/go/src/github.com/nutanix-cloud-native/ && ln -s /home/runner/work/cloud-provider-nutanix/cloud-provider-nutanix /home/runner/go/src/github.com/nutanix-cloud-native | |
- name: Run coverage report | |
run: devbox run -- make coverage | |
- name: Codecov | |
uses: codecov/codecov-action@v4.5.0 | |
env: | |
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
with: | |
file: ./coverage.xml # Replace with the path to your coverage report | |
fail_ci_if_error: true | |
- name: Run Trivy vulnerability scanner | |
uses: aquasecurity/trivy-action@0.24.0 | |
with: | |
scan-type: "fs" | |
ignore-unfixed: true | |
format: "table" | |
exit-code: "1" | |
vuln-type: "os,library" | |
severity: "CRITICAL,HIGH" | |
e2e: | |
strategy: | |
matrix: | |
e2e-labels: | |
- "capx" | |
fail-fast: false | |
uses: ./.github/workflows/e2e.yaml | |
with: | |
e2e-labels: ${{ matrix.e2e-labels }} | |
secrets: inherit | |
permissions: | |
contents: read | |
checks: write |