mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.20.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/b09bb98e06d4d774595224525879c09bc6e98c40"><code>b09bb98</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/680">#680</a> from step-security/aws-code-build</li> <li><a href="https://github.com/step-security/harden-runner/commit/35cd77bcf669054f67ffd3d2802ee54a4f13b5b6"><code>35cd77b</code></a> docs: document the Global Block List in the features list</li> <li><a href="https://github.com/step-security/harden-runner/commit/bb6dbef4bf53876cd2710acd1d36413620d20fb3"><code>bb6dbef</code></a> chore: rebuild dist with clean dependency install</li> <li><a href="https://github.com/step-security/harden-runner/commit/98f73c5a0d2b2cc518e6fb8d973a0a4dde00ba13"><code>98f73c5</code></a> chore: update eBPF agent to v1.8.14</li> <li><a href="https://github.com/step-security/harden-runner/commit/54193c17a4fa3883977217b9afe20378ebe60b19"><code>54193c1</code></a> Reapply "feat(runners): detect AWS CodeBuild-hosted runners as third-party pr...</li> <li><a href="https://github.com/step-security/harden-runner/commit/d22dd481cea4e96cedde031cfe600c248b592d54"><code>d22dd48</code></a> Revert "fix(self-hosted): flush agent events at job end when deploy-on-self-h...</li> <li><a href="https://github.com/step-security/harden-runner/commit/0ff09412fb572363b483a3c86ffe52fe61d9fd19"><code>0ff0941</code></a> fix(self-hosted): flush agent events at job end when deploy-on-self-hosted-vm...</li> <li><a href="https://github.com/step-security/harden-runner/commit/a3c333d110c8d95f34488a22e0e56742cfb1b14f"><code>a3c333d</code></a> Revert "feat(runners): detect AWS CodeBuild-hosted runners as third-party pro...</li> <li><a href="https://github.com/step-security/harden-runner/commit/bf94c00d6bba2ae7c4a479b86653039811569968"><code>bf94c00</code></a> feat(runners): detect AWS CodeBuild-hosted runners as third-party provider</li> <li><a href="https://github.com/step-security/harden-runner/commit/514522c5e449f9e28fc901f770e08a573d413e67"><code>514522c</code></a> fix(self-hosted): resolve runner user when USER env var is unset</li> <li>See full diff in <a href="https://github.com/step-security/harden-runner/compare/bf7454d06d71f1098171f2acdf0cd4708d7b5920...b09bb98e06d4d774595224525879c09bc6e98c40">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
253 lines
11 KiB
YAML
253 lines
11 KiB
YAML
name: Backend build, format check, and coverage
|
||
|
||
# Reusable workflow called from build.yml. Runs the backend build matrix
|
||
# (JDK 25 × every flavor), Spotless formatting check, JUnit, and
|
||
# posts Jacoco coverage to PRs.
|
||
#
|
||
# Flavor axis (maps to STIRLING_FLAVOR in settings.gradle):
|
||
# core - DISABLE_ADDITIONAL_FEATURES=true, no proprietary, no saas
|
||
# proprietary - default build, no saas
|
||
# saas - proprietary + the saas subproject (build + JUnit only,
|
||
# never any runtime/integration testing)
|
||
on:
|
||
workflow_call:
|
||
|
||
permissions:
|
||
contents: read
|
||
actions: read
|
||
security-events: write
|
||
pull-requests: write
|
||
|
||
jobs:
|
||
build:
|
||
runs-on: ubuntu-latest
|
||
strategy:
|
||
fail-fast: false
|
||
matrix:
|
||
jdk-version: [25]
|
||
flavor: [core, proprietary, saas]
|
||
steps:
|
||
- name: Harden Runner
|
||
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
|
||
with:
|
||
egress-policy: audit
|
||
- name: Checkout repository
|
||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||
|
||
- name: Set up JDK ${{ matrix.jdk-version }}
|
||
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
||
with:
|
||
java-version: ${{ matrix.jdk-version }}
|
||
distribution: "temurin"
|
||
|
||
- name: Cache Gradle User Home
|
||
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||
with:
|
||
path: |
|
||
~/.gradle/caches
|
||
~/.gradle/wrapper
|
||
key: gradle-${{ runner.os }}-${{ runner.arch }}-jdk-${{ matrix.jdk-version }}-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'buildSrc/**', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
||
restore-keys: |
|
||
gradle-${{ runner.os }}-${{ runner.arch }}-jdk-${{ matrix.jdk-version }}-
|
||
gradle-${{ runner.os }}-${{ runner.arch }}-
|
||
|
||
- name: Install Task
|
||
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
||
- name: Check Java formatting (Spotless)
|
||
# Runs once per matrix combination - pick the cheapest leg
|
||
# (core - no proprietary, no saas) so we don't wait for the
|
||
# heavier flavors just to fail formatting.
|
||
if: matrix.jdk-version == 25 && matrix.flavor == 'core'
|
||
id: spotless-check
|
||
run: task backend:format:check
|
||
continue-on-error: true
|
||
env:
|
||
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
||
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||
|
||
- name: Comment on backend format check failure
|
||
# Only post a comment on PRs. github-script's PR helpers need an
|
||
# issue/PR number, which doesn't exist on merge_group runs.
|
||
if: steps.spotless-check.outcome == 'failure' && github.event_name == 'pull_request'
|
||
continue-on-error: true
|
||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||
with:
|
||
script: |
|
||
const marker = '<!-- java-formatting-check -->';
|
||
const body = [
|
||
marker,
|
||
'### Backend Format Check Failed',
|
||
'',
|
||
'There are formatting issues in your Java code that will need to be fixed before they can be merged in.',
|
||
'',
|
||
'Run `task backend:format` to auto-fix, then commit and push the changes.',
|
||
].join('\n');
|
||
const { data: comments } = await github.rest.issues.listComments({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
});
|
||
const existing = comments.find(c => c.body.includes(marker));
|
||
if (existing) {
|
||
await github.rest.issues.updateComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
comment_id: existing.id,
|
||
body,
|
||
});
|
||
} else {
|
||
await github.rest.issues.createComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
body,
|
||
});
|
||
}
|
||
|
||
- name: Fail if backend format check failed
|
||
if: steps.spotless-check.outcome == 'failure'
|
||
run: |
|
||
echo "============================================"
|
||
echo " Backend Format Check Failed"
|
||
echo "============================================"
|
||
echo ""
|
||
echo "There are formatting issues in your Java code"
|
||
echo "that will need to be fixed before they can be"
|
||
echo "merged in."
|
||
echo ""
|
||
echo "Run 'task backend:format' to auto-fix, then"
|
||
echo "commit and push the changes."
|
||
echo "============================================"
|
||
exit 1
|
||
|
||
- name: Remove backend format check comment on success
|
||
if: steps.spotless-check.outcome == 'success' && github.event_name == 'pull_request'
|
||
continue-on-error: true
|
||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||
with:
|
||
script: |
|
||
const marker = '<!-- java-formatting-check -->';
|
||
const { data: comments } = await github.rest.issues.listComments({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
issue_number: context.issue.number,
|
||
});
|
||
const existing = comments.find(c => c.body.includes(marker));
|
||
if (existing) {
|
||
await github.rest.issues.deleteComment({
|
||
owner: context.repo.owner,
|
||
repo: context.repo.repo,
|
||
comment_id: existing.id,
|
||
});
|
||
}
|
||
|
||
- name: Build with Gradle (flavor=${{ matrix.flavor }})
|
||
# STIRLING_FLAVOR is read by settings.gradle and expands into the
|
||
# right combination of DISABLE_ADDITIONAL_FEATURES + ENABLE_SAAS
|
||
# so we don't have to set them by hand. The saas flavor pulls in
|
||
# the app/saas subproject (unit tests only - no runtime tests).
|
||
run: task backend:build:ci
|
||
env:
|
||
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
||
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
||
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
||
STIRLING_FLAVOR: ${{ matrix.flavor }}
|
||
# Configure the Gradle daemon explicitly; GRADLE_OPTS alone only
|
||
# configures the Gradle client JVM.
|
||
GRADLE_OPTS: '-Dorg.gradle.jvmargs=-Xmx4g -XX:+UseG1GC'
|
||
|
||
- name: Check Test Reports Exist
|
||
if: always()
|
||
run: |
|
||
# Common + core + proprietary always build (proprietary is
|
||
# excluded only at runtime, not from the gradle subproject
|
||
# graph). Saas builds add a fourth report dir.
|
||
declare -a dirs=(
|
||
"app/core/build/reports/tests/"
|
||
"app/core/build/test-results/"
|
||
"app/common/build/reports/tests/"
|
||
"app/common/build/test-results/"
|
||
"app/proprietary/build/reports/tests/"
|
||
"app/proprietary/build/test-results/"
|
||
)
|
||
if [ "${{ matrix.flavor }}" = "saas" ]; then
|
||
dirs+=("app/saas/build/reports/tests/" "app/saas/build/test-results/")
|
||
fi
|
||
for dir in "${dirs[@]}"; do
|
||
if [ ! -d "$dir" ]; then
|
||
echo "Missing $dir"
|
||
exit 1
|
||
fi
|
||
done
|
||
|
||
- name: Upload Test Reports
|
||
if: always()
|
||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||
with:
|
||
name: test-reports-jdk-${{ matrix.jdk-version }}-flavor-${{ matrix.flavor }}
|
||
path: |
|
||
app/**/build/reports/jacoco/test
|
||
app/**/build/reports/tests/
|
||
app/**/build/test-results/
|
||
app/**/build/reports/problems/
|
||
build/reports/problems/
|
||
retention-days: 3
|
||
if-no-files-found: warn
|
||
|
||
- name: Install uv
|
||
if: always() && matrix.flavor == 'saas'
|
||
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
|
||
with:
|
||
enable-cache: true
|
||
cache-dependency-glob: |
|
||
engine/pyproject.toml
|
||
engine/uv.lock
|
||
|
||
- name: JaCoCo coverage step summary
|
||
# Only the saas leg posts the JUnit summary - it's a strict
|
||
# superset of the core + proprietary legs (same .exec files plus
|
||
# the saas subproject). Posting from all three would mean three
|
||
# near-identical tables crowding out the aggregate report.
|
||
if: always() && matrix.flavor == 'saas'
|
||
run: |
|
||
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
||
--title "Backend JUnit coverage (JDK ${{ matrix.jdk-version }})" \
|
||
--jacoco "common=app/common/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "core=app/core/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "proprietary=app/proprietary/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--jacoco "saas=app/saas/build/reports/jacoco/test/jacocoTestReport.xml" \
|
||
--github-step-summary
|
||
|
||
- name: Upload raw JUnit .exec for aggregate merge
|
||
# Same dedup rationale as the summary step: upload from the saas
|
||
# leg only (the most complete set, includes app/saas/.../test.exec)
|
||
# so the aggregate workflow merges the union rather than three
|
||
# overlapping subsets.
|
||
#
|
||
# Separate artifact from the HTML reports so the aggregate
|
||
# workflow can grab just the .exec files with a name pattern
|
||
# (`jacoco-exec-*`) instead of unpacking the whole test-reports
|
||
# tarball.
|
||
if: always() && matrix.flavor == 'saas'
|
||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||
with:
|
||
name: jacoco-exec-junit-jdk-${{ matrix.jdk-version }}
|
||
path: app/*/build/jacoco/*.exec
|
||
retention-days: 7
|
||
if-no-files-found: warn
|
||
|
||
- name: Add coverage to PR (flavor=${{ matrix.flavor }}, JDK=${{ matrix.jdk-version }})
|
||
# The action only supports the pull_request event (it posts a PR comment),
|
||
# so skip it for merge_group runs and workflow_dispatch.
|
||
if: github.event_name == 'pull_request'
|
||
id: jacoco
|
||
uses: madrapps/jacoco-report@e51ce1f46f7f8b5331593f935e59cbaf44b84920 # v1.8.0
|
||
with:
|
||
paths: |
|
||
${{ github.workspace }}/**/build/reports/jacoco/test/jacocoTestReport.xml
|
||
token: ${{ secrets.GITHUB_TOKEN }}
|
||
min-coverage-overall: 10
|
||
min-coverage-changed-files: 0
|
||
comment-type: summary
|