-
Notifications
You must be signed in to change notification settings - Fork 1
131 lines (118 loc) · 4.4 KB
/
Copy pathanalysis.yml
File metadata and controls
131 lines (118 loc) · 4.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
name: Analysis
on:
pull_request:
types: [opened, reopened, synchronize, ready_for_review, converted_to_draft]
push:
branches: [main]
schedule:
- cron: "30 8 1 * *" # 8:30 UDT = 12:30 PDT, runs monthly
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions: {}
jobs:
tests-admin:
name: Unit Tests (admin)
if: (! github.event.pull_request.draft)
runs-on: ubuntu-24.04
steps:
- uses: bcgov/action-test-and-analyse@v2.0.0
with:
commands: |
cd .. && npm ci --ignore-scripts && cd -
npm run test-unit
dir: admin
# Workspaces use a single root package-lock.json; the action's npm cache
# keys on <dir>/package-lock.json (now absent), so disable it to avoid
# "Some specified paths were not resolved, unable to cache dependencies".
cache: ""
node_version: 24
knip_config: .github/knip.json
tests-api:
name: Unit Tests (api)
if: (! github.event.pull_request.draft)
runs-on: ubuntu-24.04
steps:
- uses: bcgov/action-test-and-analyse@v2.0.0
with:
commands: |
cd .. && npm ci --ignore-scripts && cd -
npm run test-unit
dir: api
# See note in tests-admin: single root lockfile -> disable per-dir npm cache.
cache: ""
node_version: 24
knip_config: .github/knip.json
sonar_token: ${{ secrets.SONAR_TOKEN }}
# npm workspaces use a single hoisted root package-lock.json, so the
# per-workspace lockfiles were removed by design.
# The root package.json still has its sibling lock.
sonar_args: >
-Dsonar.exclusions=**/*.spec.ts
-Dsonar.javascript.lcov.reportPaths=coverage/api/lcov.info
-Dsonar.organization=bcgov-sonarcloud
-Dsonar.projectKey=nr-fom
-Dsonar.issue.ignore.multicriteria=e1
-Dsonar.issue.ignore.multicriteria.e1.ruleKey=text:S8564
-Dsonar.issue.ignore.multicriteria.e1.resourceKey=**/package.json
tests-public:
name: Unit Tests (public)
if: (! github.event.pull_request.draft)
runs-on: ubuntu-24.04
steps:
- uses: bcgov/action-test-and-analyse@v2.0.0
with:
commands: |
cd .. && npm ci --ignore-scripts && cd -
npm run test-unit
dir: public
# See note in tests-admin: single root lockfile -> disable per-dir npm cache.
cache: ""
node_version: 24
knip_config: .github/knip.json
# https://github.com/marketplace/actions/aqua-security-trivy
trivy:
name: Trivy Security Scan
if: (! github.event.pull_request.draft)
permissions:
security-events: write
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v7
- name: Run Trivy vulnerability scanner in repo mode
uses: aquasecurity/trivy-action@v0.36.0
with:
format: "sarif"
output: "trivy-results.sarif"
ignore-unfixed: true
scan-type: "fs"
scanners: "vuln,secret,config"
severity: "CRITICAL,HIGH"
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: "trivy-results.sarif"
# ==========================================================================
# WARNING: This job acts as the required merge gate for this workflow.
# If you add a new job to this workflow, you MUST add its ID to the 'needs'
# array below, otherwise its failure or cancellation will not block the PR!
# ==========================================================================
results:
name: Analysis Results
needs: [tests-admin, tests-api, tests-public, trivy]
if: always()
runs-on: ubuntu-24.04
timeout-minutes: 1
steps:
- name: Log Job Results Context
run: |
echo "=== Upstream Job Statuses ==="
echo '${{ toJson(needs) }}'
- name: Evaluate Overall Status
if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
run: |
echo "❌ Critical Check Failure: At least one required job has failed or was cancelled."
exit 1
- name: Success Message
run: echo "✅ All critical checks passed or were intentionally skipped!"