php-fpm-exporter/.github/workflows/test.yml
Enrico Stahn ff74ba48e5
chore: use pull_request_target
There is no code execution that could expose secrets.
2021-04-22 10:26:37 +10:00

83 lines
1.6 KiB
YAML

name: Test
on:
pull_request_target:
workflow_dispatch:
push:
branches:
- master
- 'releases/*'
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- name: Set up Go
uses: actions/setup-go@v2.1.3
with:
go-version: 1.14
id: go
- name: Checkout
uses: actions/checkout@v2
- name: golangci-lint
uses: golangci/golangci-lint-action@v2
with:
version: v1.32
test:
name: Test
runs-on: ubuntu-latest
steps:
- name: Setup Go
uses: actions/setup-go@v2.1.3
with:
go-version: ^1.15.0
id: go
- name: Checkout
uses: actions/checkout@v2
- name: Test
run: go test -coverprofile cover.out ./...
- name: SonarCloud Scan
uses: sonarsource/sonarcloud-github-action@master
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
image-scan:
name: Image Scan
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Unshallow
run: git fetch --prune --unshallow
- name: Setup Go
uses: actions/setup-go@v2.1.3
with:
go-version: ^1.15.0
id: go
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@v2.2.1
with:
version: latest
args: release --rm-dist --skip-validate --skip-publish
key: ${{ secrets.YOUR_PRIVATE_KEY }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Scan image
uses: anchore/scan-action@v2
with:
image: "hipages/php-fpm_exporter:latest"
fail-build: true