mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.21.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.21.0</h2> <h2>What's Changed</h2> <ul> <li>Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.</li> <li>Improved Support for AWS CodeBuild GitHub Actions Runners.</li> <li>Bug fixes.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0">https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0</a></p> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/05e31511f85b41b11d1cf0ef85d0992719546e2c"><code>05e3151</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/684">#684</a> from step-security/rc-42</li> <li><a href="https://github.com/step-security/harden-runner/commit/0f37afa338f57c61ee3dfc274daca8834963d83e"><code>0f37afa</code></a> fix: ignore denied-endpoints on non-enterprise tier</li> <li><a href="https://github.com/step-security/harden-runner/commit/93b58ee491c5b6cf3a5324966fca2908f8d447f3"><code>93b58ee</code></a> fix: resolve cache host read-first and never downgrade egress policy</li> <li><a href="https://github.com/step-security/harden-runner/commit/e7399dd3e93d6c159d314af54b4704bc48abf6bc"><code>e7399dd</code></a> fix: align deny-list mode detection with agent and log when both endpoint inp...</li> <li><a href="https://github.com/step-security/harden-runner/commit/c16689f716a10cdfd9cfe22e63938b8c6c0657de"><code>c16689f</code></a> test: add denied_endpoints to Configuration fixtures and cover deny-list merge</li> <li><a href="https://github.com/step-security/harden-runner/commit/40b99cf0c7161e4dcdc6c5508927188b65028df9"><code>40b99cf</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/682">#682</a> from rohan-stepsecurity/rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/fedec027a205365a7d64001a81931e4c36a1af6e"><code>fedec02</code></a> Merge branch 'rc-42' into rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/5361fb178b926b2be6df52e11ee257823821567b"><code>5361fb1</code></a> feat: add build artifacts</li> <li><a href="https://github.com/step-security/harden-runner/commit/286474fffe0b8fe7c9db855f132d04a9b48ab564"><code>286474f</code></a> feat: Support Bravo agent install on CodeBuild runners</li> <li><a href="https://github.com/step-security/harden-runner/commit/051ec05283d064bd82f41279db4f70f0717bf778"><code>051ec05</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/683">#683</a> from h0x0er/jatin/deny-list</li> <li>Additional commits viewable in <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...05e31511f85b41b11d1cf0ef85d0992719546e2c">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
253 lines
11 KiB
YAML
253 lines
11 KiB
YAML
name: Backend build, format check, and coverage
|
||
|
||
# Reusable workflow called from build.yml. Runs the backend build matrix
|
||
# (JDK 25 × every flavor), Spotless formatting check, JUnit, and
|
||
# posts Jacoco coverage to PRs.
|
||
#
|
||
# Flavor axis (maps to STIRLING_FLAVOR in settings.gradle):
|
||
# core - DISABLE_ADDITIONAL_FEATURES=true, no proprietary, no saas
|
||
# proprietary - default build, no saas
|
||
# saas - proprietary + the saas subproject (build + JUnit only,
|
||
# never any runtime/integration testing)
|
||
on:
|
||
workflow_call:
|
||
|
||
permissions:
|
||
contents: read
|
||
actions: read
|
||
security-events: write
|
||
pull-requests: write
|
||
|
||
jobs:
|
||
build:
|
||
environment:
|
||
name: ci-unsigned
|
||
deployment: false
|
||
runs-on: ubuntu-latest
|
||
strategy:
|
||
fail-fast: false
|
||
matrix:
|
||
jdk-version: [25]
|
||
flavor: [core, proprietary, saas]
|
||
steps:
|
||
- name: Harden Runner
|
||
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
|
||
with:
|
||
egress-policy: audit
|
||
- name: Checkout repository
|
||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||
|
||
- name: Restore cache Gradle User Home
|
||
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||
with:
|
||
path: |
|
||
~/.gradle/caches
|
||
~/.gradle/wrapper
|
||
key: gradle-v1-${{ runner.os }}-${{ runner.arch }}-jdk-${{ matrix.jdk-version }}-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'buildSrc/**', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
||
|
||
- name: Set up JDK ${{ matrix.jdk-version }}
|
||
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
||
with:
|
||
java-version: ${{ matrix.jdk-version }}
|
||
distribution: "temurin"
|
||
|
||
- name: Install Task
|
||
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
||
- name: Check Java formatting (Spotless)
|
||
# Runs once per matrix combination - pick the cheapest leg
|
||
# (core - no proprietary, no saas) so we don't wait for the
|
||
# heavier flavors just to fail formatting.
|
||
if: matrix.jdk-version == 25 && matrix.flavor == 'core'
|
||
id: spotless-check
|
||
run: task backend:format:check
|
||
continue-on-error: true
|
||
env:
|
||
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
||
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||
|
||
- name: Comment on backend format check failure
|
||
# Only post a comment on PRs. github-script's PR helpers need an
|
||
# issue/PR number, which doesn't exist on merge_group runs.
|
||
if: steps.spotless-check.outcome == 'failure' && github.event_name == 'pull_request'
|
||
continue-on-error: true
|
||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||
with:
|
||
script: |
|
||
const marker = '<!-- java-formatting-check -->';
|
||
const body = [
|
||
marker,
|
||
'### Backend Format Check Failed',
|
||
'',
|
||
'There are formatting issues in your Java code that will need to be fixed before they can be merged in.',
|
||
'',
|
||
'Run `task backend:format` to auto-fix, then commit and push the changes.',
|
||
].join('\n');
|
||
const { data: comments } = await github.rest.issues.listComments({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
});
|
||
const existing = comments.find(c => c.body.includes(marker));
|
||
if (existing) {
|
||
await github.rest.issues.updateComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
comment_id: existing.id,
|
||
body,
|
||
});
|
||
} else {
|
||
await github.rest.issues.createComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
body,
|
||
});
|
||
}
|
||
|
||
- name: Fail if backend format check failed
|
||
if: steps.spotless-check.outcome == 'failure'
|
||
run: |
|
||
echo "============================================"
|
||
echo " Backend Format Check Failed"
|
||
echo "============================================"
|
||
echo ""
|
||
echo "There are formatting issues in your Java code"
|
||
echo "that will need to be fixed before they can be"
|
||
echo "merged in."
|
||
echo ""
|
||
echo "Run 'task backend:format' to auto-fix, then"
|
||
echo "commit and push the changes."
|
||
echo "============================================"
|
||
exit 1
|
||
|
||
- name: Remove backend format check comment on success
|
||
if: steps.spotless-check.outcome == 'success' && github.event_name == 'pull_request'
|
||
continue-on-error: true
|
||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||
with:
|
||
script: |
|
||
const marker = '<!-- java-formatting-check -->';
|
||
const { data: comments } = await github.rest.issues.listComments({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
});
|
||
const existing = comments.find(c => c.body.includes(marker));
|
||
if (existing) {
|
||
await github.rest.issues.deleteComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
comment_id: existing.id,
|
||
});
|
||
}
|
||
|
||
- name: Build with Gradle (flavor=${{ matrix.flavor }})
|
||
# STIRLING_FLAVOR is read by settings.gradle and expands into the
|
||
# right combination of DISABLE_ADDITIONAL_FEATURES + ENABLE_SAAS
|
||
# so we don't have to set them by hand. The saas flavor pulls in
|
||
# the app/saas subproject (unit tests only - no runtime tests).
|
||
run: task backend:build:ci
|
||
env:
|
||
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
||
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||
STIRLING_FLAVOR: ${{ matrix.flavor }}
|
||
# Configure the Gradle daemon explicitly; GRADLE_OPTS alone only
|
||
# configures the Gradle client JVM.
|
||
GRADLE_OPTS: "-Dorg.gradle.jvmargs=-Xmx4g -XX:+UseG1GC"
|
||
|
||
- name: Check Test Reports Exist
|
||
if: always()
|
||
run: |
|
||
# Common + core + proprietary always build (proprietary is
|
||
# excluded only at runtime, not from the gradle subproject
|
||
# graph). Saas builds add a fourth report dir.
|
||
declare -a dirs=(
|
||
"app/core/build/reports/tests/"
|
||
"app/core/build/test-results/"
|
||
"app/common/build/reports/tests/"
|
||
"app/common/build/test-results/"
|
||
"app/proprietary/build/reports/tests/"
|
||
"app/proprietary/build/test-results/"
|
||
)
|
||
if [ "${{ matrix.flavor }}" = "saas" ]; then
|
||
dirs+=("app/saas/build/reports/tests/" "app/saas/build/test-results/")
|
||
fi
|
||
for dir in "${dirs[@]}"; do
|
||
if [ ! -d "$dir" ]; then
|
||
echo "Missing $dir"
|
||
exit 1
|
||
fi
|
||
done
|
||
|
||
- name: Upload Test Reports
|
||
if: always()
|
||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||
with:
|
||
name: test-reports-jdk-${{ matrix.jdk-version }}-flavor-${{ matrix.flavor }}
|
||
path: |
|
||
app/**/build/reports/jacoco/test
|
||
app/**/build/reports/tests/
|
||
app/**/build/test-results/
|
||
app/**/build/reports/problems/
|
||
build/reports/problems/
|
||
retention-days: 3
|
||
if-no-files-found: warn
|
||
|
||
- name: Install uv
|
||
if: always() && matrix.flavor == 'saas'
|
||
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
||
with:
|
||
enable-cache: true
|
||
cache-dependency-glob: |
|
||
engine/pyproject.toml
|
||
engine/uv.lock
|
||
|
||
- name: JaCoCo coverage step summary
|
||
# Only the saas leg posts the JUnit summary - it's a strict
|
||
# superset of the core + proprietary legs (same .exec files plus
|
||
# the saas subproject). Posting from all three would mean three
|
||
# near-identical tables crowding out the aggregate report.
|
||
if: always() && matrix.flavor == 'saas'
|
||
run: |
|
||
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
||
--title "Backend JUnit coverage (JDK ${{ matrix.jdk-version }})" \
|
||
--jacoco "common=app/common/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "core=app/core/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "proprietary=app/proprietary/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "saas=app/saas/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--github-step-summary
|
||
|
||
- name: Upload raw JUnit .exec for aggregate merge
|
||
# Same dedup rationale as the summary step: upload from the saas
|
||
# leg only (the most complete set, includes app/saas/.../test.exec)
|
||
# so the aggregate workflow merges the union rather than three
|
||
# overlapping subsets.
|
||
#
|
||
# Separate artifact from the HTML reports so the aggregate
|
||
# workflow can grab just the .exec files with a name pattern
|
||
# (`jacoco-exec-*`) instead of unpacking the whole test-reports
|
||
# tarball.
|
||
if: always() && matrix.flavor == 'saas'
|
||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||
with:
|
||
name: jacoco-exec-junit-jdk-${{ matrix.jdk-version }}
|
||
path: app/*/build/jacoco/*.exec
|
||
retention-days: 7
|
||
if-no-files-found: warn
|
||
|
||
- name: Add coverage to PR (flavor=${{ matrix.flavor }}, JDK=${{ matrix.jdk-version }})
|
||
# The action only supports the pull_request event (it posts a PR comment),
|
||
# so skip it for merge_group runs and workflow_dispatch.
|
||
if: github.event_name == 'pull_request'
|
||
id: jacoco
|
||
uses: madrapps/jacoco-report@e51ce1f46f7f8b5331593f935e59cbaf44b84920 # v1.8.0
|
||
with:
|
||
paths: |
|
||
${{ github.workspace }}/**/build/reports/jacoco/test/jacocoTestReport.xml
|
||
token: ${{ secrets.GITHUB_TOKEN }}
|
||
min-coverage-overall: 10
|
||
min-coverage-changed-files: 0
|
||
comment-type: summary
|