Skip to content

fix CVE issues

fix CVE issues #125

Workflow file for this run

name: CI
on:
pull_request:
workflow_dispatch:
jobs:
lint:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Install Go
uses: actions/setup-go@v6
with:
go-version-file: "go.mod"
cache-dependency-path: "go.sum"
- name: Lint code
uses: golangci/golangci-lint-action@v9
with:
version: v2.6
working-directory: .
build:
needs: lint
runs-on: ubuntu-latest
strategy:
matrix:
component: [server, worker, pogocache]
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build ${{ matrix.component }} Docker image
uses: docker/build-push-action@v6
with:
context: .
file: docker/${{ matrix.component }}.Dockerfile
push: false
tags: nadmax/nexq-${{ matrix.component }}:${{ github.sha }}
outputs: type=docker,dest=/tmp/${{ matrix.component }}-image.tar
- name: Upload ${{ matrix.component }} image artifact
uses: actions/upload-artifact@v4
with:
name: ${{ matrix.component }}-image
path: /tmp/${{ matrix.component }}-image.tar
retention-days: 1
security-code:
needs: build
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Install Go
uses: actions/setup-go@v6
with:
go-version-file: "go.mod"
cache-dependency-path: "go.sum"
- name: Install Trivy
uses: aquasecurity/setup-trivy@v0.2.0
with:
cache: true
version: v0.68.2
- name: Run Gosec Security Scanner
uses: securego/gosec@master
with:
args: "-tests -no-fail -fmt sarif -out gosec-results.sarif ./..."
- name: Upload Gosec scan results
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: "gosec-results.sarif"
- name: Scan code dependencies
uses: aquasecurity/trivy-action@0.33.1
with:
scan-type: "fs"
scan-ref: "."
severity: "HIGH"
format: "sarif"
output: "trivy-dependencies-results.sarif"
skip-setup-trivy: true
- name: Upload code dependencies scan results
uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: "trivy-dependencies-results.sarif"
security-image:
needs: build
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
strategy:
matrix:
component: [server, worker, pogocache]
steps:
- name: Install Trivy
uses: aquasecurity/setup-trivy@v0.2.0
with:
cache: true
version: v0.68.2
- name: Download ${{ matrix.component }} image artifact
uses: actions/download-artifact@v4
with:
name: ${{ matrix.component }}-image
path: /tmp
- name: Load Docker image
run: docker load --input /tmp/${{ matrix.component }}-image.tar
- name: Scan ${{ matrix.component }} Docker image
uses: aquasecurity/trivy-action@0.33.1
with:
image-ref: nadmax/nexq-${{ matrix.component }}:${{ github.sha }}
format: "sarif"
severity: "HIGH"
output: "trivy-${{ matrix.component }}-results.sarif"
skip-setup-trivy: true
- name: Upload Docker images scan results
uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: "trivy-${{ matrix.component }}-results.sarif"
category: ${{ matrix.component }}
test:
needs: build
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Install Go
uses: actions/setup-go@v6
with:
go-version-file: "go.mod"
cache-dependency-path: "go.sum"
- name: Run tests
run: go test -v ./...