Skip to content

feat(hooks): scan the pushed revision range in pre-push #312

feat(hooks): scan the pushed revision range in pre-push

feat(hooks): scan the pushed revision range in pre-push #312

Workflow file for this run

name: CI-push
on:
push:
branches:
- master
merge_group:
types:
- checks_requested
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
CARGO_INCREMENTAL: 0
CARGO_NET_RETRY: 10
RUSTUP_MAX_RETRIES: 10
RUST_BACKTRACE: short
jobs:
self-scan:
name: Self scan
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Install Rust
uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- name: Build
run: cargo build --release --locked
# KeyWatch must be clean under its own rules, and the committed
# baseline must still describe this tree.
- name: Scan this repository
run: ./target/release/key-watch scan .
- name: Baseline is current
run: |
./target/release/key-watch scan . --update-baseline
git diff --exit-code -- .keywatch-baseline.json
- name: Framework integration uses the staged scan
run: grep -q "scan --staged" .pre-commit-hooks.yaml
distribution:
name: distribution
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Validate GitHub Action and release automation
run: python3 scripts/action_validation/validate.py
- name: Build container
run: docker build --tag keywatch:ci .
- name: Smoke-test container
shell: bash
run: |
set -euo pipefail
docker run --rm keywatch:ci --version
test "$(docker run --rm --entrypoint id keywatch:ci -u)" != "0"
set +e
printf '%s\n' 'AWS_KEY=AKIAABCDEFGHIJKLMNOP' | \
docker run --rm -i keywatch:ci scan --stdin --exit-mode strict
scan_status=$?
set -e
if [ "$scan_status" -ne 1 ]; then
echo "ERROR: container secret scan exited with $scan_status instead of 1" >&2
exit 1
fi
formatting:
name: cargo-fmt
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Install Rust
uses: dtolnay/rust-toolchain@master
with:
toolchain: nightly
components: rustfmt
- name: Check formatting
shell: bash
run: cargo +nightly fmt --all --check
typos:
name: spell-check
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Spell check
uses: crate-ci/typos@v1.48.0
test:
name: test-${{ matrix.runner }}
runs-on: ${{ matrix.runner }}
timeout-minutes: 30
env:
RUSTFLAGS: "-D warnings"
strategy:
fail-fast: true
matrix:
runner:
- ubuntu-latest
- macos-latest
- windows-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Install mold linker
uses: rui314/setup-mold@v1
if: ${{ runner.os == 'Linux' }}
with:
make-default: true
- name: Install Rust
uses: dtolnay/rust-toolchain@master
with:
toolchain: stable 2 weeks ago
components: clippy
- uses: Swatinem/rust-cache@v2.9.1
with:
save-if: ${{ github.event_name == 'push' }}
# Full suite across all targets and features; fmt and clippy run
# in their own jobs.
- name: Run tests
run: cargo test --all-features --all-targets
- name: Run tests (release)
run: cargo test --release --all-features --all-targets
- name: Run Clippy
run: cargo clippy --all-features --all-targets -- -D warnings