Skip to content

chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to … #23

chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to …

chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to … #23

Workflow file for this run

# cid-workflow-version: 0.11.0
# This file is generated by the CID Workflow GitHub App.
# DO NOT EDIT!
# name
name: 'CI - Main'
# triggers
on:
workflow_dispatch:
inputs:
loglevel:
description: Log level
required: true
default: info
type: choice
options:
- trace
- debug
- info
- warn
- error
push:
branches:
- main
paths-ignore:
- 'README.md'
- 'LICENSE'
- '.gitignore'
- '.gitattributes'
- '.editorconfig'
- 'renovate.json'
- 'CODEOWNERS'
- 'SECURITY.md'
# permissions, see https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions and https://docs.github.com/en/rest/overview/permissions-required-for-github-apps
permissions:
actions: read # required: detect GitHub Actions runtime environment
checks: none # not required
contents: read # required: read repository content
deployments: none # not required
id-token: none # not required
issues: none # not required
packages: none # not required
pages: none # not required
pull-requests: none # not required
repository-projects: none # not required
security-events: none # not required
statuses: none # not required
# cancel in progress when a new run starts
concurrency:
group: "${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}"
cancel-in-progress: true
env:
CID_WORKFLOW: 'main'
CID_LOGLEVEL: "${{ github.event.inputs.loglevel || 'info' }}"
# allowed modes are 'block' and 'audit'. Using https://github.com/step-security/harden-runner to harden the runner.
EGRESS_POLICY: 'block'
# jobs
jobs:
# go-build [github.com/cidverse/cid]
go-build-github-com-cidverse-cid:
name: 'go-build [github.com/cidverse/cid]'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
proxy.golang.org:443
storage.googleapis.com:443
sum.golang.org:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - go-build [github.com/cidverse/cid]
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "go-build-github-com-cidverse-cid"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "go-build-github-com-cidverse-cid-${{ github.run_id }}"
path: ".dist/go-build-github-com-cidverse-cid/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# go-test [github.com/cidverse/cid]
go-test-github-com-cidverse-cid:
name: 'go-test [github.com/cidverse/cid]'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
proxy.golang.org:443
storage.googleapis.com:443
sum.golang.org:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - go-test [github.com/cidverse/cid]
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "go-test-github-com-cidverse-cid"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "go-test-github-com-cidverse-cid-${{ github.run_id }}"
path: ".dist/go-test-github-com-cidverse-cid/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# golangci-lint [github.com/cidverse/cid]
golangci-lint-github-com-cidverse-cid:
name: 'golangci-lint [github.com/cidverse/cid]'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
security-events: write # required: upload security events
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
proxy.golang.org:443
storage.googleapis.com:443
sum.golang.org:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - golangci-lint [github.com/cidverse/cid]
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "golangci-lint-github-com-cidverse-cid"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "golangci-lint-github-com-cidverse-cid-${{ github.run_id }}"
path: ".dist/golangci-lint-github-com-cidverse-cid/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# gitleaks-scan
gitleaks-scan:
name: 'gitleaks-scan'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
security-events: write # required: upload security events
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - gitleaks-scan
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "gitleaks-scan"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "gitleaks-scan-${{ github.run_id }}"
path: ".dist/gitleaks-scan/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# semgrep-scan
semgrep-scan:
name: 'semgrep-scan'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
security-events: write # required: upload security events
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
semgrep.dev:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - semgrep-scan
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
SEMGREP_RULES: "${{ secrets.SEMGREP_RULES || vars.SEMGREP_RULES }}"
SEMGREP_APP_TOKEN: "${{ secrets.SEMGREP_APP_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "semgrep-scan"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "semgrep-scan-${{ github.run_id }}"
path: ".dist/semgrep-scan/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# trivyfs-scan
trivyfs-scan:
name: 'trivyfs-scan'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
security-events: write # required: upload security events
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
mirror.gcr.io:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - trivyfs-scan
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "trivyfs-scan"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "trivyfs-scan-${{ github.run_id }}"
path: ".dist/trivyfs-scan/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# zizmor-scan
zizmor-scan:
name: 'zizmor-scan'
runs-on: ubuntu-24.04
permissions:
id-token: write # provenance signing
security-events: write # required: upload security events
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Action - zizmor-scan
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
GH_HOSTNAME: "${{ secrets.GH_HOSTNAME || vars.GH_HOSTNAME }}"
GH_TOKEN: "${{ secrets.GH_TOKEN || vars.GH_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "zizmor-scan"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "zizmor-scan-${{ github.run_id }}"
path: ".dist/zizmor-scan/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true
# sonarqube-scan
sonarqube-scan:
name: 'sonarqube-scan'
runs-on: ubuntu-24.04
needs: [go-test-github-com-cidverse-cid]
permissions:
id-token: write # provenance signing
timeout-minutes: 10
steps:
- name: Harden Runner
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
with:
disable-telemetry: true
egress-policy: "${{ env.EGRESS_POLICY }}"
allowed-endpoints: >-
sonarcloud.io:443
api.sonarcloud.io:443
scanner.sonarcloud.io:443
keyserver.ubuntu.com:443
github.com:443
api.github.com:443
codeload.github.com:443
uploads.github.com:443
objects.githubusercontent.com:443
raw.githubusercontent.com:443
release-assets.githubusercontent.com:443
ghcr.io:443
pkg-containers.githubusercontent.com:443
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
- name: Prepare Tooling
shell: bash
run: bash .cid/scripts/install.sh "0.11.0" "54a17e1d59e924e4e612efc33fc33a855806e3aaf120dec88fca94101e452beb" "76A4948E69C62589C7B0AB84E414434DF5371FB6"
- name: Download Inputs > go-test-github-com-cidverse-cid
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: "go-test-github-com-cidverse-cid-${{ github.run_id }}"
path: ".dist/go-test-github-com-cidverse-cid"
continue-on-error: true
- name: Action - sonarqube-scan
env:
CID_WORKFLOW: "${{ env.CID_WORKFLOW }}"
CID_LOGLEVEL: "${{ env.CID_LOGLEVEL }}"
GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
SONAR_HOST_URL: "${{ secrets.SONAR_HOST_URL || vars.SONAR_HOST_URL }}"
SONAR_ORGANIZATION: "${{ secrets.SONAR_ORGANIZATION || vars.SONAR_ORGANIZATION }}"
SONAR_PROJECTKEY: "${{ secrets.SONAR_PROJECTKEY || vars.SONAR_PROJECTKEY }}"
SONAR_DEFAULT_BRANCH: "${{ secrets.SONAR_DEFAULT_BRANCH || vars.SONAR_DEFAULT_BRANCH }}"
SONAR_REGION: "${{ secrets.SONAR_REGION || vars.SONAR_REGION }}"
SONAR_TOKEN: "${{ secrets.SONAR_TOKEN }}"
run: |
cid --log-level=${CID_LOGLEVEL:-info} plan execute --state-file ".cid/state-github.json" --state-wf-name "main" --step "sonarqube-scan"
- name: Upload Outputs
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: "sonarqube-scan-${{ github.run_id }}"
path: ".dist/sonarqube-scan/"
retention-days: 1
if-no-files-found: ignore
compression-level: 6
include-hidden-files: true