feat(hooks): scan the pushed revision range in pre-push #312
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI-push | |
| on: | |
| push: | |
| branches: | |
| - master | |
| merge_group: | |
| types: | |
| - checks_requested | |
| pull_request: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| CARGO_INCREMENTAL: 0 | |
| CARGO_NET_RETRY: 10 | |
| RUSTUP_MAX_RETRIES: 10 | |
| RUST_BACKTRACE: short | |
| jobs: | |
| self-scan: | |
| name: Self scan | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@master | |
| with: | |
| toolchain: stable | |
| - name: Build | |
| run: cargo build --release --locked | |
| # KeyWatch must be clean under its own rules, and the committed | |
| # baseline must still describe this tree. | |
| - name: Scan this repository | |
| run: ./target/release/key-watch scan . | |
| - name: Baseline is current | |
| run: | | |
| ./target/release/key-watch scan . --update-baseline | |
| git diff --exit-code -- .keywatch-baseline.json | |
| - name: Framework integration uses the staged scan | |
| run: grep -q "scan --staged" .pre-commit-hooks.yaml | |
| distribution: | |
| name: distribution | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v7 | |
| - name: Validate GitHub Action and release automation | |
| run: python3 scripts/action_validation/validate.py | |
| - name: Build container | |
| run: docker build --tag keywatch:ci . | |
| - name: Smoke-test container | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| docker run --rm keywatch:ci --version | |
| test "$(docker run --rm --entrypoint id keywatch:ci -u)" != "0" | |
| set +e | |
| printf '%s\n' 'AWS_KEY=AKIAABCDEFGHIJKLMNOP' | \ | |
| docker run --rm -i keywatch:ci scan --stdin --exit-mode strict | |
| scan_status=$? | |
| set -e | |
| if [ "$scan_status" -ne 1 ]; then | |
| echo "ERROR: container secret scan exited with $scan_status instead of 1" >&2 | |
| exit 1 | |
| fi | |
| formatting: | |
| name: cargo-fmt | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v7 | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@master | |
| with: | |
| toolchain: nightly | |
| components: rustfmt | |
| - name: Check formatting | |
| shell: bash | |
| run: cargo +nightly fmt --all --check | |
| typos: | |
| name: spell-check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v7 | |
| - name: Spell check | |
| uses: crate-ci/typos@v1.48.0 | |
| test: | |
| name: test-${{ matrix.runner }} | |
| runs-on: ${{ matrix.runner }} | |
| timeout-minutes: 30 | |
| env: | |
| RUSTFLAGS: "-D warnings" | |
| strategy: | |
| fail-fast: true | |
| matrix: | |
| runner: | |
| - ubuntu-latest | |
| - macos-latest | |
| - windows-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v7 | |
| - name: Install mold linker | |
| uses: rui314/setup-mold@v1 | |
| if: ${{ runner.os == 'Linux' }} | |
| with: | |
| make-default: true | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@master | |
| with: | |
| toolchain: stable 2 weeks ago | |
| components: clippy | |
| - uses: Swatinem/rust-cache@v2.9.1 | |
| with: | |
| save-if: ${{ github.event_name == 'push' }} | |
| # Full suite across all targets and features; fmt and clippy run | |
| # in their own jobs. | |
| - name: Run tests | |
| run: cargo test --all-features --all-targets | |
| - name: Run tests (release) | |
| run: cargo test --release --all-features --all-targets | |
| - name: Run Clippy | |
| run: cargo clippy --all-features --all-targets -- -D warnings |