forked from hyphanet/fred
-
Notifications
You must be signed in to change notification settings - Fork 0
119 lines (102 loc) · 4.54 KB
/
Copy pathbuild.yml
File metadata and controls
119 lines (102 loc) · 4.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
name: Build cryptad artifacts
on:
workflow_call:
inputs:
git-ref:
type: string
default: main
jdk-version:
type: string
default: '25'
outputs:
artifact-id:
description: The artifact-id for built cryptad.jar
value: ${{ jobs.build.outputs.artifact-id }}
secrets:
SONAR_TOKEN:
description: SonarCloud token forwarded from caller
required: false
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
actions: write # required for actions/cache to reserve/upload caches
attestations: write
id-token: write
# Expose selected secrets as env so we can use them in step `if:`
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
outputs:
artifact-id: ${{ steps.upload-artifact.outputs.artifact-id}}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: crypta-network/cryptad
ref: ${{ inputs.git-ref }}
fetch-depth: 0 # Required for Sonar analysis accuracy
- name: Set up JDK
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
java-version: ${{ inputs.jdk-version }}
distribution: 'temurin'
# Cache SonarQube packages to speed up analysis
- name: Cache SonarQube packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.sonar/cache
key: ${{ runner.os }}-sonar
restore-keys: ${{ runner.os }}-sonar
# Configure Gradle for optimal use in GitHub Actions, including caching of downloaded dependencies.
# See: https://github.com/gradle/actions/blob/main/setup-gradle/README.md
- name: Setup Gradle
uses: gradle/actions/setup-gradle@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0
- name: Install Gradle properties
uses: ./.github/actions/setup-gradle-properties
- name: Prepare bounded CI report retention
env:
PYTHONPATH: tools/release-certification
run: python3 -m cryptad_certification.phase_12_ci --prepare "$RUNNER_TEMP/phase12-report-start.json"
- name: Build and analyze (Gradle)
if: ${{ env.SONAR_TOKEN != '' }}
env:
GITHUB_TOKEN: ${{ github.token }}
SONAR_TOKEN: ${{ env.SONAR_TOKEN }}
run: ./gradlew build errorproneReport sonar --warning-mode all
- name: Build (no Sonar token)
if: ${{ env.SONAR_TOKEN == '' }}
env:
GITHUB_TOKEN: ${{ github.token }}
run: ./gradlew build errorproneReport
# The producer exports only typed counts and public source identities. Raw JUnit output,
# diagnostic messages, source paths and private-payload hashes never become artifacts.
- name: Retain typed CI test and analyzer facts
if: success() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
env:
PYTHONPATH: tools/release-certification
run: python3 -m cryptad_certification.phase_12_ci --retain "$RUNNER_TEMP/phase12-report-facts" --started "$RUNNER_TEMP/phase12-report-start.json"
- name: Attest exact CI report facts
if: success() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: ${{ runner.temp }}/phase12-report-facts/phase-12-ci-reports.json
- name: Upload bounded CI report facts
if: success() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository)
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: phase-12-ci-reports-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/phase12-report-facts/phase-12-ci-reports.json
if-no-files-found: error
retention-days: 14
include-hidden-files: false
- name: Upload cryptad.jar
id: upload-artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: cryptad
path: build/libs/cryptad.jar
- name: Upload jlink tarball
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: cryptad-jlink
path: build/distributions/cryptad-jlink-v*.tar.gz