mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.3 to 2.20.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.20.0</h2> <h2>What's Changed</h2> <ul> <li>Support for block policy for MacOS and Windows GitHub-hosted runners</li> <li>Support for Bitrise MacOS GitHub Actions runners</li> <li>HTTPS monitoring support for Bun for Linux runners (enterprise tier)</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.19.4...v2.20.0">https://github.com/step-security/harden-runner/compare/v2.19.4...v2.20.0</a></p> <h2>v2.19.4</h2> <h2>What's Changed</h2> <ul> <li>Improvements for HTTPS Monitoring for the Enterprise tier of Harden Runner</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.19.3...v2.19.4">https://github.com/step-security/harden-runner/compare/v2.19.3...v2.19.4</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/bf7454d06d71f1098171f2acdf0cd4708d7b5920"><code>bf7454d</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/673">#673</a> from step-security/fix/aggregate-error-startup-hang</li> <li><a href="https://github.com/step-security/harden-runner/commit/1188420976b49762617c32cc010cba50a9fd7a71"><code>1188420</code></a> Update non-TLS agent to v0.16.2</li> <li><a href="https://github.com/step-security/harden-runner/commit/162cfeac170141192dc6d57ade86ddf59448ad96"><code>162cfea</code></a> Update non-TLS agent to v0.16.1</li> <li><a href="https://github.com/step-security/harden-runner/commit/eb9e1f4943b602b6f338f6f79468e812c2c6b320"><code>eb9e1f4</code></a> Bring macOS runner updates from PR 674</li> <li><a href="https://github.com/step-security/harden-runner/commit/1a10b01783c147498a6dee4fa4e7122325762720"><code>1a10b01</code></a> Update Windows agent to v1.0.7</li> <li><a href="https://github.com/step-security/harden-runner/commit/8b4a105ef5119b20c97c1566b0275b9399ae188d"><code>8b4a105</code></a> Apply npm audit fixes with release-age cooldown</li> <li><a href="https://github.com/step-security/harden-runner/commit/3626e0327723bef1c4e6b01750518eccd380a5df"><code>3626e03</code></a> Default TLS status check failures to enabled</li> <li><a href="https://github.com/step-security/harden-runner/commit/100e08b39cfd419c292df7becc379b0305ac0628"><code>100e08b</code></a> Update agent-ebpf to v1.8.12</li> <li><a href="https://github.com/step-security/harden-runner/commit/774f75f2c6334606d2d3d910a663f93c9ea49b3b"><code>774f75f</code></a> Update agent to v1.8.9</li> <li><a href="https://github.com/step-security/harden-runner/commit/f312657a64c745fae39c2c66cc7c7f7bc4c804d8"><code>f312657</code></a> Extend missing-agent-dir guard to Linux and macOS cleanup paths</li> <li>Additional commits viewable in <a href="https://github.com/step-security/harden-runner/compare/ab7a9404c0f3da075243ca237b5fac12c98deaa5...bf7454d06d71f1098171f2acdf0cd4708d7b5920">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
187 lines
7.6 KiB
YAML
187 lines
7.6 KiB
YAML
name: Docker Compose Cucumber tests
|
|
|
|
# Reusable workflow called from build.yml when project / docker / testing
|
|
# sources change. Boots the docker-compose stack and runs the cucumber
|
|
# scenarios in testing/cucumber.
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
docker-base-changed:
|
|
description: "Whether the docker base image changed (forwarded from files-changed)."
|
|
required: false
|
|
type: string
|
|
default: "false"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
docker-compose-tests:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
actions: write
|
|
contents: read
|
|
checks: write
|
|
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout Repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
|
|
with:
|
|
java-version: "25"
|
|
distribution: "temurin"
|
|
|
|
- name: Cache Gradle dependency artifacts
|
|
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: |
|
|
~/.gradle/wrapper
|
|
~/.gradle/caches/modules-2/files-2.1
|
|
~/.gradle/caches/modules-2/metadata-2.*
|
|
key: gradle-deps-${{ runner.os }}-jdk-25-${{ hashFiles('**/gradle/wrapper/gradle-wrapper.properties', '**/*.gradle', '**/*.gradle.kts', 'settings.gradle', 'settings.gradle.kts', 'gradle/libs.versions.toml') }}
|
|
|
|
- name: Setup Gradle
|
|
uses: gradle/actions/setup-gradle@3f131e8634966bd73d06cc69884922b02e6faf92 # v6.2.0
|
|
with:
|
|
gradle-version: 9.6.1
|
|
cache-disabled: true
|
|
|
|
# When the PR changes the base image, test.sh builds it locally
|
|
# (stirling-pdf-base:local) into the daemon image store. A buildx
|
|
# container builder can't see that store, so skip it here and let
|
|
# `docker buildx build` fall back to the default docker driver, which
|
|
# resolves the local base. The gha cache backend is also skipped (its
|
|
# runtime token isn't exposed) since the docker driver can't use it.
|
|
- name: Set up Docker Buildx
|
|
if: inputs.docker-base-changed != 'true'
|
|
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
|
|
|
|
# Expose ACTIONS_RUNTIME_TOKEN / ACTIONS_RESULTS_URL for docker buildx type=gha cache backend.
|
|
- name: Expose GitHub runtime for Buildx cache
|
|
if: inputs.docker-base-changed != 'true'
|
|
uses: crazy-max/ghaction-github-runtime@04d248b84655b509d8c44dc1d6f990c879747487 # v4.0.0
|
|
|
|
- name: Install Docker Compose
|
|
run: |
|
|
sudo curl -SL "https://github.com/docker/compose/releases/download/v2.39.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose
|
|
sudo chmod +x /usr/local/bin/docker-compose
|
|
|
|
- name: Set up Python
|
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
|
with:
|
|
python-version: "3.12"
|
|
cache: "pip" # caching pip dependencies
|
|
cache-dependency-path: ./testing/cucumber/requirements.txt
|
|
|
|
- name: Pip requirements
|
|
run: |
|
|
pip install --require-hashes --only-binary=:all: -r ./testing/cucumber/requirements.txt
|
|
|
|
- name: Extract JaCoCo agent for cucumber coverage
|
|
# Stages build/jacoco/jacocoagent.jar where the coverage override
|
|
# file bind-mounts it into the cucumber container. The agent jar
|
|
# never goes into the published image - this is host-only.
|
|
run: ./gradlew copyJacocoAgent -PnoSpotless
|
|
|
|
- name: Run Docker Compose Tests
|
|
run: |
|
|
chmod +x ./testing/test_webpages.sh
|
|
chmod +x ./testing/test.sh
|
|
chmod +x ./testing/test_disabledEndpoints.sh
|
|
./testing/test.sh
|
|
env:
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
DOCKER_BASE_CHANGED: ${{ inputs.docker-base-changed }}
|
|
# Tells test.sh to layer testing/compose/docker-compose-coverage.override.yml
|
|
# over the cucumber compose so the container starts with the
|
|
# JaCoCo agent attached via JAVA_CUSTOM_OPTS.
|
|
STIRLING_PDF_TEST_COVERAGE: "1"
|
|
|
|
- name: Generate cucumber JaCoCo report
|
|
# `if: always()` so a behave failure still produces partial
|
|
# coverage from whatever endpoints did run. The exec file only
|
|
# exists when the container shut down cleanly - guard so the step
|
|
# is silent on the (rare) crash path.
|
|
if: always()
|
|
id: cucumber-coverage
|
|
run: |
|
|
if [ -s testing/cucumber-coverage/cucumber.exec ]; then
|
|
./gradlew jacocoReportFromExec \
|
|
-PexecFile=testing/cucumber-coverage/cucumber.exec \
|
|
-PreportDir=build/reports/jacoco/cucumber \
|
|
-PnoSpotless
|
|
echo "report=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "::warning::No cucumber .exec at testing/cucumber-coverage/cucumber.exec (container may have crashed before flushing)"
|
|
echo "report=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Install defusedxml for coverage summary
|
|
# coverage-summary.py parses JaCoCo XML through defusedxml -
|
|
# see the script header for context.
|
|
if: always() && steps.cucumber-coverage.outputs.report == 'true'
|
|
run: python -m pip install --quiet defusedxml
|
|
|
|
- name: Cucumber coverage step summary
|
|
if: always() && steps.cucumber-coverage.outputs.report == 'true'
|
|
run: |
|
|
python scripts/coverage-summary.py \
|
|
--title "Cucumber (docker) JaCoCo coverage" \
|
|
--jacoco "cucumber=build/reports/jacoco/cucumber/jacocoTestReport.xml" \
|
|
--github-step-summary
|
|
|
|
- name: Upload cucumber JaCoCo report
|
|
if: always() && steps.cucumber-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-cucumber-${{ github.run_id }}
|
|
path: build/reports/jacoco/cucumber/
|
|
retention-days: 7
|
|
|
|
- name: Upload raw cucumber .exec for aggregate merge
|
|
# Picked up by the coverage-aggregate workflow via the
|
|
# `jacoco-exec-*` artifact name pattern.
|
|
if: always() && steps.cucumber-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-exec-cucumber
|
|
path: testing/cucumber-coverage/cucumber.exec
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Upload Cucumber Report
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: cucumber-report
|
|
path: testing/cucumber/report.html
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Upload Test Reports
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: docker-compose-test-reports
|
|
path: testing/reports/
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Cucumber Test Report
|
|
if: always()
|
|
uses: dorny/test-reporter@a43b3a5f7366b97d083190328d2c652e1a8b6aa2 # v3.0.0
|
|
with:
|
|
name: Cucumber Tests
|
|
path: testing/cucumber/junit/*.xml
|
|
reporter: java-junit
|
|
fail-on-error: false
|