mirror of
https://github.com/ko-build/ko.git
synced 2026-06-18 20:14:08 +02:00
Take advantage of Chainguard maintained versions of various actions. (#609)
* Take advantage of Chainguard maintained versions of various actions. * Bump cosign version
This commit is contained in:
@@ -4,3 +4,7 @@ updates:
|
|||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
interval: "weekly"
|
interval: "weekly"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: /
|
||||||
|
schedule:
|
||||||
|
interval: weekly
|
||||||
|
|||||||
@@ -24,47 +24,9 @@ jobs:
|
|||||||
language: Bash
|
language: Bash
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/setup-go@v2
|
|
||||||
with:
|
|
||||||
go-version: 1.17.x
|
|
||||||
|
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v2
|
||||||
|
|
||||||
- name: Install Tools
|
- uses: chainguard-dev/actions/boilerplate@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
run: |
|
with:
|
||||||
TEMP_PATH="$(mktemp -d)"
|
extension: ${{ matrix.extension }}
|
||||||
cd $TEMP_PATH
|
language: ${{ matrix.language }}
|
||||||
|
|
||||||
echo '::group::🐶 Installing reviewdog ... https://github.com/reviewdog/reviewdog'
|
|
||||||
curl -sfL https://raw.githubusercontent.com/reviewdog/reviewdog/master/install.sh | sh -s -- -b "${TEMP_PATH}" 2>&1
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo '::group:: Installing boilerplate-check ... https://github.com/mattmoor/boilerplate-check'
|
|
||||||
go get github.com/mattmoor/boilerplate-check/cmd/boilerplate-check
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo "${TEMP_PATH}" >> $GITHUB_PATH
|
|
||||||
|
|
||||||
- name: ${{ matrix.language }} license boilerplate
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
|
||||||
|
|
||||||
echo '::group:: Running github.com/mattmoor/boilerplate-check for ${{ matrix.language }} with reviewdog 🐶 ...'
|
|
||||||
# Don't fail because of boilerplate-check
|
|
||||||
set +o pipefail
|
|
||||||
boilerplate-check check \
|
|
||||||
--boilerplate ./hack/boilerplate/boilerplate.${{ matrix.extension }}.txt \
|
|
||||||
--file-extension ${{ matrix.extension }} \
|
|
||||||
--exclude "(vendor|third_party)/" |
|
|
||||||
reviewdog -efm="%A%f:%l: %m" \
|
|
||||||
-efm="%C%.%#" \
|
|
||||||
-name="${{ matrix.language }} headers" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="diff_context" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|||||||
@@ -11,32 +11,5 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v2
|
||||||
- name: Do Not Submit
|
- uses: chainguard-dev/actions/donotsubmit@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
|
||||||
|
|
||||||
TEMP_PATH="$(mktemp -d)"
|
|
||||||
PATH="${TEMP_PATH}:$PATH"
|
|
||||||
|
|
||||||
echo '::group::🐶 Installing reviewdog ... https://github.com/reviewdog/reviewdog'
|
|
||||||
curl -sfL https://raw.githubusercontent.com/reviewdog/reviewdog/master/install.sh | sh -s -- -b "${TEMP_PATH}" 2>&1
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo '::group:: Running DO NOT SUBMIT with reviewdog 🐶 ...'
|
|
||||||
# Don't fail because of grep
|
|
||||||
set +o pipefail
|
|
||||||
find . -type f -not -path './vendor/*' -not -path './third_party/*' -not -path './.git/*' -not -path './.github/workflows/*' |
|
|
||||||
xargs grep -n "DO NOT SUBMIT" |
|
|
||||||
reviewdog -efm="%f:%l:%m" \
|
|
||||||
-name="DO NOT SUBMIT" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="added" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|||||||
@@ -26,46 +26,16 @@ jobs:
|
|||||||
- name: Install ko
|
- name: Install ko
|
||||||
run: go install ./
|
run: go install ./
|
||||||
|
|
||||||
- name: Configure KinD Cluster
|
- name: Setup Cluster
|
||||||
run: |
|
uses: chainguard-dev/actions/setup-kind@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
# KinD configuration.
|
|
||||||
cat > kind.yaml <<EOF
|
|
||||||
apiVersion: kind.x-k8s.io/v1alpha4
|
|
||||||
kind: Cluster
|
|
||||||
|
|
||||||
# Configure registry for KinD.
|
|
||||||
containerdConfigPatches:
|
|
||||||
- |-
|
|
||||||
[plugins."io.containerd.grpc.v1.cri".registry.mirrors."$REGISTRY_NAME:$REGISTRY_PORT"]
|
|
||||||
endpoint = ["http://$REGISTRY_NAME:$REGISTRY_PORT"]
|
|
||||||
EOF
|
|
||||||
|
|
||||||
- uses: helm/kind-action@v1.2.0
|
|
||||||
with:
|
with:
|
||||||
cluster_name: kind
|
k8s-version: v1.23.x
|
||||||
config: kind.yaml
|
registry-authority: ${{ env.REGISTRY_NAME }}:${{ env.REGISTRY_PORT }}
|
||||||
|
|
||||||
- name: Setup local registry
|
|
||||||
run: |
|
|
||||||
# Run a registry.
|
|
||||||
docker run -d --restart=always \
|
|
||||||
-p $REGISTRY_PORT:$REGISTRY_PORT --name $REGISTRY_NAME registry:2
|
|
||||||
|
|
||||||
# Connect the registry to the KinD network.
|
|
||||||
docker network connect "kind" $REGISTRY_NAME
|
|
||||||
|
|
||||||
# Make the $REGISTRY_NAME -> 127.0.0.1, to tell `ko` to publish to
|
|
||||||
# local reigstry, even when pushing $REGISTRY_NAME:$REGISTRY_PORT/some/image
|
|
||||||
sudo echo "127.0.0.1 $REGISTRY_NAME" | sudo tee -a /etc/hosts
|
|
||||||
|
|
||||||
- name: Wait for ready nodes
|
|
||||||
run: |
|
|
||||||
kubectl wait --timeout=2m --for=condition=Ready nodes --all
|
|
||||||
|
|
||||||
- name: Install Cosign
|
- name: Install Cosign
|
||||||
uses: sigstore/cosign-installer@main
|
uses: sigstore/cosign-installer@main
|
||||||
with:
|
with:
|
||||||
cosign-release: 'v1.3.1'
|
cosign-release: 'v1.5.1'
|
||||||
|
|
||||||
- name: Run Smoke Test
|
- name: Run Smoke Test
|
||||||
run: |
|
run: |
|
||||||
@@ -101,14 +71,6 @@ jobs:
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Collect logs
|
- name: Collect diagnostics and upload
|
||||||
if: ${{ always() }}
|
if: ${{ failure() }}
|
||||||
run: |
|
uses: chainguard-dev/actions/kind-diag@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
mkdir -p /tmp/logs
|
|
||||||
kind export logs /tmp/logs
|
|
||||||
- name: Upload artifacts
|
|
||||||
if: ${{ always() }}
|
|
||||||
uses: actions/upload-artifact@v2
|
|
||||||
with:
|
|
||||||
name: logs
|
|
||||||
path: /tmp/logs
|
|
||||||
|
|||||||
+36
-192
@@ -6,214 +6,58 @@ on:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
|
|
||||||
autoformat:
|
gofmt:
|
||||||
name: Auto-format and Check
|
name: check gofmt
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
strategy:
|
|
||||||
fail-fast: false # Keep running if one leg fails.
|
|
||||||
matrix:
|
|
||||||
tool:
|
|
||||||
- goimports
|
|
||||||
- gofmt
|
|
||||||
|
|
||||||
include:
|
|
||||||
- tool: gofmt
|
|
||||||
options: -s
|
|
||||||
- tool: goimports
|
|
||||||
importpath: golang.org/x/tools/cmd/goimports
|
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/setup-go@v2
|
- uses: actions/setup-go@v2
|
||||||
with:
|
with:
|
||||||
go-version: 1.17.x
|
go-version: 1.17.x
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v2
|
||||||
|
- uses: chainguard-dev/actions/gofmt@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
|
with:
|
||||||
|
args: -s
|
||||||
|
|
||||||
- name: Install Dependencies
|
goimports:
|
||||||
if: ${{ matrix.importpath != '' }}
|
name: check goimports
|
||||||
run: |
|
runs-on: ubuntu-latest
|
||||||
cd $(mktemp -d)
|
steps:
|
||||||
GO111MODULE=on go get ${{ matrix.importpath }}
|
- uses: actions/setup-go@v2
|
||||||
|
with:
|
||||||
- name: ${{ matrix.tool }} ${{ matrix.options }}
|
go-version: 1.17.x
|
||||||
run: >
|
- uses: actions/checkout@v2
|
||||||
${{ matrix.tool }} ${{ matrix.options }} -w
|
- uses: chainguard-dev/actions/goimports@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
$(find .
|
|
||||||
-path './vendor' -prune
|
|
||||||
-o -path './third_party' -prune
|
|
||||||
-o -name '*.pb.go' -prune
|
|
||||||
-o -name 'wire_gen.go' -prune
|
|
||||||
-o -type f -name '*.go' -print)
|
|
||||||
|
|
||||||
- name: Verify ${{ matrix.tool }}
|
|
||||||
run: |
|
|
||||||
# From: https://backreference.org/2009/12/23/how-to-match-newlines-in-sed/
|
|
||||||
# This is to leverage this workaround:
|
|
||||||
# https://github.com/actions/toolkit/issues/193#issuecomment-605394935
|
|
||||||
function urlencode() {
|
|
||||||
sed ':begin;$!N;s/\n/%0A/;tbegin'
|
|
||||||
}
|
|
||||||
if [[ $(git diff-index --name-only HEAD --) ]]; then
|
|
||||||
for x in $(git diff-index --name-only HEAD --); do
|
|
||||||
echo "::error file=$x::Please run ${{ matrix.tool }} ${{ matrix.options }}.%0A$(git diff $x | urlencode)"
|
|
||||||
done
|
|
||||||
echo "${{ github.repository }} is out of style. Please run ${{ matrix.tool }} ${{ matrix.options }}."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "${{ github.repository }} is formatted correctly."
|
|
||||||
|
|
||||||
lint:
|
lint:
|
||||||
name: Lint
|
name: Lint
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/setup-go@v2
|
- name: Set up Go
|
||||||
|
uses: actions/setup-go@v2
|
||||||
with:
|
with:
|
||||||
go-version: 1.17.x
|
go-version: 1.17.x
|
||||||
- uses: actions/checkout@v2
|
|
||||||
|
|
||||||
- uses: golangci/golangci-lint-action@v2
|
- name: Check out code
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- uses: chainguard-dev/actions/trailing-space@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
|
if: ${{ always() }}
|
||||||
|
|
||||||
|
- uses: chainguard-dev/actions/eof-newline@84c993eaf02da1c325854fb272a4df9184bd80fc # main
|
||||||
|
if: ${{ always() }}
|
||||||
|
|
||||||
|
- uses: reviewdog/action-misspell@v1
|
||||||
|
if: ${{ always() }}
|
||||||
with:
|
with:
|
||||||
version: v1.43
|
github_token: ${{ secrets.github_token }}
|
||||||
|
fail_on_error: true
|
||||||
|
locale: "US"
|
||||||
|
|
||||||
- name: Install Tools
|
- uses: get-woke/woke-action-reviewdog@v0
|
||||||
env:
|
|
||||||
WOKE_VERSION: v0.5.0
|
|
||||||
run: |
|
|
||||||
TEMP_PATH="$(mktemp -d)"
|
|
||||||
cd $TEMP_PATH
|
|
||||||
|
|
||||||
echo '::group::🐶 Installing reviewdog ... https://github.com/reviewdog/reviewdog'
|
|
||||||
curl -sfL https://raw.githubusercontent.com/reviewdog/reviewdog/master/install.sh | sh -s -- -b "${TEMP_PATH}" 2>&1
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo '::group:: Installing misspell ... https://github.com/client9/misspell'
|
|
||||||
go get github.com/client9/misspell/cmd/misspell
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo '::group:: Installing woke ... https://github.com/get-woke/woke'
|
|
||||||
curl -sfL https://raw.githubusercontent.com/get-woke/woke/main/install.sh | sh -s -- -b "${TEMP_PATH}" "${WOKE_VERSION}" 2>&1
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
echo "${TEMP_PATH}" >> $GITHUB_PATH
|
|
||||||
|
|
||||||
- name: misspell
|
|
||||||
if: ${{ always() }}
|
if: ${{ always() }}
|
||||||
env:
|
with:
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
github-token: ${{ secrets.github_token }}
|
||||||
run: |
|
reporter: github-pr-check
|
||||||
set -e
|
level: error
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
fail-on-error: true
|
||||||
|
|
||||||
echo '::group:: Running github.com/client9/misspell with reviewdog 🐶 ...'
|
|
||||||
# Don't fail because of misspell
|
|
||||||
set +o pipefail
|
|
||||||
# Exclude generated and vendored files, plus some legacy
|
|
||||||
# paths until we update all .gitattributes
|
|
||||||
git ls-files |
|
|
||||||
git check-attr --stdin linguist-generated | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
git check-attr --stdin linguist-vendored | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
grep -Ev '^(vendor/|third_party/|.git)' |
|
|
||||||
xargs misspell -i importas -error |
|
|
||||||
reviewdog -efm="%f:%l:%c: %m" \
|
|
||||||
-name="github.com/client9/misspell" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="added" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
- name: trailing whitespace
|
|
||||||
if: ${{ always() }}
|
|
||||||
env:
|
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
|
||||||
|
|
||||||
echo '::group:: Flagging trailing whitespace with reviewdog 🐶 ...'
|
|
||||||
# Don't fail because of grep
|
|
||||||
set +o pipefail
|
|
||||||
|
|
||||||
# Exclude generated and vendored files, plus some legacy
|
|
||||||
# paths until we update all .gitattributes
|
|
||||||
git ls-files |
|
|
||||||
git check-attr --stdin linguist-generated | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
git check-attr --stdin linguist-vendored | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
grep -Ev '^(vendor/|third_party/|.git)' |
|
|
||||||
xargs grep -nE " +$" |
|
|
||||||
reviewdog -efm="%f:%l:%m" \
|
|
||||||
-name="trailing whitespace" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="added" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
- name: EOF newline
|
|
||||||
if: ${{ always() }}
|
|
||||||
env:
|
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
|
||||||
|
|
||||||
echo '::group:: Flagging missing EOF newlines with reviewdog 🐶 ...'
|
|
||||||
# Don't fail because of misspell
|
|
||||||
set +o pipefail
|
|
||||||
# Lint exclude rule:
|
|
||||||
# - nothing in vendor/
|
|
||||||
# - nothing in third_party
|
|
||||||
# - nothing in .git/
|
|
||||||
# - no *.ai (Adobe Illustrator) files.
|
|
||||||
LINT_FILES=$(git ls-files |
|
|
||||||
git check-attr --stdin linguist-generated | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
git check-attr --stdin linguist-vendored | grep -Ev ': (set|true)$' | cut -d: -f1 |
|
|
||||||
grep -Ev '^(vendor/|third_party/|.git)' |
|
|
||||||
grep -v '\.ai$')
|
|
||||||
|
|
||||||
for x in $LINT_FILES; do
|
|
||||||
# Based on https://stackoverflow.com/questions/34943632/linux-check-if-there-is-an-empty-line-at-the-end-of-a-file
|
|
||||||
if [[ -f $x && ! ( -s "$x" && -z "$(tail -c 1 $x)" ) ]]; then
|
|
||||||
# We add 1 to `wc -l` here because of this limitation (from the man page):
|
|
||||||
# Characters beyond the final <newline> character will not be included in the line count.
|
|
||||||
echo $x:$((1 + $(wc -l $x | tr -s ' ' | cut -d' ' -f 1))): Missing newline
|
|
||||||
fi
|
|
||||||
done |
|
|
||||||
reviewdog -efm="%f:%l: %m" \
|
|
||||||
-name="EOF Newline" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="added" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|
||||||
# This is mostly copied from https://github.com/get-woke/woke-action-reviewdog/blob/main/entrypoint.sh
|
|
||||||
# since their action is not yet released under a stable version.
|
|
||||||
- name: Language
|
|
||||||
if: ${{ always() && github.event_name == 'pull_request' }}
|
|
||||||
env:
|
|
||||||
REVIEWDOG_GITHUB_API_TOKEN: ${{ github.token }}
|
|
||||||
run: |
|
|
||||||
set -e
|
|
||||||
cd "${GITHUB_WORKSPACE}" || exit 1
|
|
||||||
|
|
||||||
# Create a minimal .wokeignore if none already exist.
|
|
||||||
if [ ! -f .wokeignore ]; then
|
|
||||||
cat > .wokeignore <<EOF
|
|
||||||
vendor/*
|
|
||||||
third_party/*
|
|
||||||
EOF
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo '::group:: Running woke with reviewdog 🐶 ...'
|
|
||||||
woke --output simple \
|
|
||||||
| reviewdog -efm="%f:%l:%c: %m" \
|
|
||||||
-name="woke" \
|
|
||||||
-reporter="github-pr-check" \
|
|
||||||
-filter-mode="added" \
|
|
||||||
-fail-on-error="true" \
|
|
||||||
-level="error"
|
|
||||||
echo '::endgroup::'
|
|
||||||
|
|||||||
Reference in New Issue
Block a user