Skip to content

Bump actions/checkout from 4 to 7 (#15) #22

Bump actions/checkout from 4 to 7 (#15)

Bump actions/checkout from 4 to 7 (#15) #22

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
jobs:
validate:
name: Validate (dotnet build + test, fmt, validate, tflint, trivy)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-dotnet@v6
with:
dotnet-version: "10.0.x"
- name: Build the function and the tests
run: dotnet build FindNextCIDRRange.sln -c Release
- name: Unit tests (the contract guard)
run: dotnet test FindNextCIDRRange.sln -c Release --no-build
- uses: hashicorp/setup-terraform@v4
with:
terraform_version: "~> 1.9"
- name: Terraform fmt
run: terraform -chdir=terraform fmt -check -recursive
- name: Validate the stack
run: |
set -euo pipefail
terraform -chdir=terraform init -backend=false -input=false >/dev/null
terraform -chdir=terraform validate
- name: Setup TFLint
uses: terraform-linters/setup-tflint@6e1e0642c0289bd619021bf6b34e3c08ed1e005a # v6.3.0
- name: TFLint
run: |
set -euo pipefail
( cd terraform && tflint --init && tflint --recursive )
# The trivyignores input is avoided on purpose: trivy-action concatenates the listed files
# into an extension-less temp file, and trivy decides the ignore-file format by extension,
# so a YAML waiver file silently stops matching. The TRIVY_IGNOREFILE env var hands trivy
# the file directly, extension intact.
- name: Trivy config scan (report CRITICAL to LOW, non-blocking)
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
env:
TRIVY_IGNOREFILE: .trivyignore.yaml
with:
scan-type: config
scan-ref: .
severity: CRITICAL,HIGH,MEDIUM,LOW
exit-code: "0"
- name: Trivy config gate (fail on HIGH or CRITICAL)
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
env:
TRIVY_IGNOREFILE: .trivyignore.yaml
with:
scan-type: config
scan-ref: .
severity: CRITICAL,HIGH
exit-code: "1"