Bump actions/checkout from 4 to 7 (#15) #22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| name: Validate (dotnet build + test, fmt, validate, tflint, trivy) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-dotnet@v6 | |
| with: | |
| dotnet-version: "10.0.x" | |
| - name: Build the function and the tests | |
| run: dotnet build FindNextCIDRRange.sln -c Release | |
| - name: Unit tests (the contract guard) | |
| run: dotnet test FindNextCIDRRange.sln -c Release --no-build | |
| - uses: hashicorp/setup-terraform@v4 | |
| with: | |
| terraform_version: "~> 1.9" | |
| - name: Terraform fmt | |
| run: terraform -chdir=terraform fmt -check -recursive | |
| - name: Validate the stack | |
| run: | | |
| set -euo pipefail | |
| terraform -chdir=terraform init -backend=false -input=false >/dev/null | |
| terraform -chdir=terraform validate | |
| - name: Setup TFLint | |
| uses: terraform-linters/setup-tflint@6e1e0642c0289bd619021bf6b34e3c08ed1e005a # v6.3.0 | |
| - name: TFLint | |
| run: | | |
| set -euo pipefail | |
| ( cd terraform && tflint --init && tflint --recursive ) | |
| # The trivyignores input is avoided on purpose: trivy-action concatenates the listed files | |
| # into an extension-less temp file, and trivy decides the ignore-file format by extension, | |
| # so a YAML waiver file silently stops matching. The TRIVY_IGNOREFILE env var hands trivy | |
| # the file directly, extension intact. | |
| - name: Trivy config scan (report CRITICAL to LOW, non-blocking) | |
| uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 | |
| env: | |
| TRIVY_IGNOREFILE: .trivyignore.yaml | |
| with: | |
| scan-type: config | |
| scan-ref: . | |
| severity: CRITICAL,HIGH,MEDIUM,LOW | |
| exit-code: "0" | |
| - name: Trivy config gate (fail on HIGH or CRITICAL) | |
| uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 | |
| env: | |
| TRIVY_IGNOREFILE: .trivyignore.yaml | |
| with: | |
| scan-type: config | |
| scan-ref: . | |
| severity: CRITICAL,HIGH | |
| exit-code: "1" |