Guest User

Untitled

a guest
Sep 23rd, 2026
42
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.04 KB | None | 0 0
  1. ---
  2. name: ci
  3.  
  4. on:
  5. push:
  6. branches: [main, dev]
  7. pull_request: {}
  8.  
  9. jobs:
  10. test:
  11. runs-on: debian-13
  12. steps:
  13. - uses: actions/checkout@v4
  14. - name: Run CI tests
  15. run: |
  16. set -euxo pipefail
  17. pwd
  18. ls -l Makefile
  19. command -v make
  20. command -v go
  21. command -v node
  22. command -v python3
  23. go version
  24. node --version
  25. make ci-test
  26.  
  27. build:
  28. if: github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/dev')
  29. needs: test
  30. runs-on: scrapecast-build
  31. permissions:
  32. contents: read
  33. packages: write
  34. steps:
  35. - uses: actions/checkout@v4
  36. - name: Login to the loopback Forgejo registry
  37. env:
  38. REGISTRY_USERNAME: "${{ secrets.REGISTRY_USERNAME }}"
  39. REGISTRY_PASSWORD: "${{ secrets.REGISTRY_PASSWORD }}"
  40. run: |
  41. set -euo pipefail
  42. # Runner PrivateTmp hides /tmp from the user Podman service. Keep
  43. # remote client files in the workspace so login, push, and Cosign
  44. # see the same Docker-compatible auth file.
  45. export DOCKER_CONFIG="${GITHUB_WORKSPACE}/.ci-registry"
  46. mkdir -p "$DOCKER_CONFIG"
  47. REGISTRY_AUTH="$(printf '%s:%s' "$REGISTRY_USERNAME" "$REGISTRY_PASSWORD" | base64 -w0)"
  48. printf '{"auths":{"127.0.0.1:13000":{"auth":"%s"}}}\n' \
  49. "$REGISTRY_AUTH" > "$DOCKER_CONFIG/config.json"
  50. chmod 0600 "$DOCKER_CONFIG/config.json"
  51. - name: Build and push images
  52. env:
  53. COSIGN_PRIVATE_KEY: "${{ secrets.COSIGN_PRIVATE_KEY }}"
  54. COSIGN_PASSWORD: "${{ secrets.COSIGN_PASSWORD }}"
  55. run: |
  56. set -euo pipefail
  57. REG=127.0.0.1:13000
  58. NS="${{ forgejo.repository }}"
  59. SHA="${{ forgejo.sha }}"
  60. export DOCKER_CONFIG="${GITHUB_WORKSPACE}/.ci-registry"
  61. COSIGN_HOME="$XDG_CACHE_HOME/cosign-home"
  62. mkdir -p "$COSIGN_HOME" "$DOCKER_CONFIG"
  63. case "${{ github.ref_name }}" in
  64. main|dev) CHANNEL="${{ github.ref_name }}" ;;
  65. *) echo "unsupported deployment branch" >&2; exit 1 ;;
  66. esac
  67. for img in scraper web evasion; do
  68. podman --remote build --pull=newer \
  69. -t "$REG/$NS/$img:$SHA" \
  70. -t "$REG/$NS/$img:$CHANNEL" \
  71. "./$img"
  72. trivy image \
  73. --image-src podman \
  74. --scanners vuln \
  75. --report summary \
  76. --ignore-unfixed \
  77. --severity HIGH,CRITICAL \
  78. --exit-code 1 \
  79. "$REG/$NS/$img:$CHANNEL"
  80. podman --remote push \
  81. --authfile "$DOCKER_CONFIG/config.json" \
  82. --tls-verify=false \
  83. "$REG/$NS/$img:$SHA"
  84. DIGEST_FILE="$DOCKER_CONFIG/${img}.digest"
  85. : > "$DIGEST_FILE"
  86. podman --remote push \
  87. --authfile "$DOCKER_CONFIG/config.json" \
  88. --digestfile "$DIGEST_FILE" \
  89. --tls-verify=false \
  90. "$REG/$NS/$img:$CHANNEL"
  91. DIGEST="$(tr -d '\n' < "$DIGEST_FILE")"
  92. if ! printf '%s\n' "$DIGEST" | grep -Eq '^sha256:[0-9a-f]{64}$'; then
  93. DIGEST="$(podman --remote image inspect --format '{{.Digest}}' \
  94. "$REG/$NS/$img:$CHANNEL")"
  95. fi
  96. if ! printf '%s\n' "$DIGEST" | grep -Eq '^sha256:[0-9a-f]{64}$'; then
  97. echo "registry returned an invalid image digest" >&2
  98. exit 1
  99. fi
  100. HOME="$COSIGN_HOME" COSIGN_PASSWORD="$COSIGN_PASSWORD" \
  101. cosign sign --yes \
  102. --allow-insecure-registry \
  103. --key env://COSIGN_PRIVATE_KEY \
  104. --annotations "repository=$NS" \
  105. --annotations "branch=$CHANNEL" \
  106. "$REG/$NS/$img@$DIGEST"
  107. podman --remote rmi "$REG/$NS/$img:$SHA" || true
  108. done
  109. podman --remote image prune --force
  110.  
Add Comment
Please, Sign In to add comment