-
Notifications
You must be signed in to change notification settings - Fork 1
ci: add GitHub Actions CI workflow (mirrors gts-go/gts-rust/gts-ts) #4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| root = true | ||
|
|
||
| # Baseline whitespace conventions enforced by `make fmt` (dotnet format). | ||
| # Kept intentionally minimal so the formatter's built-in C# defaults apply | ||
| # without imposing heavy style opinions. | ||
| [*] | ||
| charset = utf-8 | ||
| end_of_line = lf | ||
| insert_final_newline = true | ||
| trim_trailing_whitespace = true | ||
| indent_style = space | ||
|
|
||
| [*.cs] | ||
| indent_size = 4 | ||
|
|
||
| [*.{csproj,props,targets}] | ||
| indent_size = 2 | ||
|
|
||
| [*.{json,yml,yaml}] | ||
| indent_size = 2 |
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,149 @@ | ||||||
| name: CI | ||||||
|
|
||||||
| on: | ||||||
| push: | ||||||
| branches: [ main, develop ] | ||||||
| paths-ignore: | ||||||
| - '**/*.md' | ||||||
| - 'docs/**' | ||||||
| pull_request: | ||||||
| branches: [ main, develop ] | ||||||
| paths-ignore: | ||||||
| - '**/*.md' | ||||||
| - 'docs/**' | ||||||
|
|
||||||
| # Cancel previous runs for the same ref to save CI minutes. | ||||||
| concurrency: | ||||||
| group: ci-${{ github.workflow }}-${{ github.ref }} | ||||||
| cancel-in-progress: true | ||||||
|
|
||||||
| permissions: | ||||||
| contents: read | ||||||
|
|
||||||
| env: | ||||||
| DOTNET_NOLOGO: 'true' | ||||||
| DOTNET_CLI_TELEMETRY_OPTOUT: 'true' | ||||||
| DOTNET_SKIP_FIRST_TIME_EXPERIENCE: 'true' | ||||||
|
|
||||||
| jobs: | ||||||
| test: | ||||||
| name: Test Suite (${{ matrix.os }}) | ||||||
| runs-on: ${{ matrix.os }} | ||||||
| strategy: | ||||||
| fail-fast: false | ||||||
| matrix: | ||||||
| os: [ ubuntu-latest, windows-latest, macos-latest ] | ||||||
|
|
||||||
| steps: | ||||||
| - name: Force LF in working tree (w/a for Windows) | ||||||
| if: runner.os == 'Windows' | ||||||
| shell: bash | ||||||
| run: | | ||||||
| git config --global core.autocrlf false | ||||||
| git config --global core.eol lf | ||||||
|
|
||||||
| - name: Checkout | ||||||
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 | ||||||
| with: | ||||||
| clean: 'true' | ||||||
| persist-credentials: false | ||||||
|
|
||||||
| # Install the .NET 8 SDK for the net8.0 target. global.json intentionally | ||||||
| # stays permissive ("8.0.0" + rollForward=latestMajor, i.e. "min .NET 8, | ||||||
| # use whatever newer SDK is present"); that pin is not a downloadable | ||||||
| # build, so we install an 8.0 SDK explicitly rather than via global.json. | ||||||
| - name: Set up .NET | ||||||
| uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 | ||||||
| with: | ||||||
| dotnet-version: '8.0.x' | ||||||
|
|
||||||
| - name: Show .NET version | ||||||
| run: dotnet --info | ||||||
|
|
||||||
| - name: Restore | ||||||
| run: dotnet restore gts-dotnet.sln | ||||||
|
|
||||||
| # Formatting check (fast fail for style issues) | ||||||
| - name: dotnet format (check) | ||||||
| run: make fmt | ||||||
|
|
||||||
| # Analyzers (linter) | ||||||
| - name: dotnet format analyzers (check) | ||||||
| run: make lint | ||||||
|
|
||||||
| # Build | ||||||
| - name: build | ||||||
| run: dotnet build gts-dotnet.sln -c Release --no-restore | ||||||
|
|
||||||
| # Unit tests | ||||||
| - name: test | ||||||
| run: dotnet test gts-dotnet.sln -c Release --no-build | ||||||
|
|
||||||
| security: | ||||||
| name: Security (dotnet list package --vulnerable on Ubuntu) | ||||||
| runs-on: ubuntu-latest | ||||||
| steps: | ||||||
| - name: Checkout | ||||||
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 | ||||||
| with: | ||||||
| persist-credentials: false | ||||||
|
|
||||||
| - name: Set up .NET | ||||||
| uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 | ||||||
| with: | ||||||
| dotnet-version: '8.0.x' | ||||||
|
|
||||||
| - name: Restore | ||||||
| run: dotnet restore gts-dotnet.sln | ||||||
|
|
||||||
| # Report vulnerable NuGet dependencies but do not fail CI. | ||||||
| - name: dotnet list package --vulnerable | ||||||
| run: make security | ||||||
| continue-on-error: true | ||||||
|
|
||||||
| coverage: | ||||||
| name: Code Coverage | ||||||
| runs-on: ubuntu-latest | ||||||
| steps: | ||||||
| - name: Checkout | ||||||
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 | ||||||
| with: | ||||||
| persist-credentials: false | ||||||
|
|
||||||
| - name: Set up .NET | ||||||
| uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 | ||||||
| with: | ||||||
| dotnet-version: '8.0.x' | ||||||
|
|
||||||
| # Generate a Cobertura coverage report. | ||||||
| - name: Run tests with coverage | ||||||
| run: dotnet test gts-dotnet.sln -c Release --collect:"XPlat Code Coverage" | ||||||
|
|
||||||
| # Upload to Codecov; do not fail CI if Codecov is down/misconfigured. | ||||||
| - name: Upload to Codecov | ||||||
| uses: codecov/codecov-action@0f8570b1a125f4937846a11fcfa3bcd548bd8c97 # v4.6.0 | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: gh api repos/codecov/codecov-action/commits/0f8570b1a125f4937846a11fcfa3bcd548bd8c97 --jq '.sha'
gh api repos/codecov/codecov-action/git/ref/tags/v4.6.0 --jq '.object'Repository: GlobalTypeSystem/gts-dotnet Length of output: 594 🏁 Script executed: set -eu
tag_object='0f8570b1a125f4937846a11fcfa3bcd548bd8c97'
commit_sha="$(gh api "repos/codecov/codecov-action/git/tags/${tag_object}" --jq '.object.sha')"
printf 'resolved_commit=%s\n' "$commit_sha"
gh api "repos/codecov/codecov-action/commits/${commit_sha}" --jq '{sha: .sha, message: .commit.message}'
printf 'v4.6.0_ref=\n'
gh api repos/codecov/codecov-action/git/ref/tags/v4.6.0 --jq '{sha: .object.sha, type: .object.type}'Repository: GlobalTypeSystem/gts-dotnet Length of output: 390 Pin Codecov to the v4.6.0 commit. The current value is an annotated tag object, not a commit SHA. GitHub cannot resolve it as a commit pin. Use the commit behind Suggested fix- uses: codecov/codecov-action@0f8570b1a125f4937846a11fcfa3bcd548bd8c97 # v4.6.0
+ uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||
| with: | ||||||
| files: '**/coverage.cobertura.xml' | ||||||
| fail_ci_if_error: false | ||||||
| # token: ${{ secrets.CODECOV_TOKEN }} # Uncomment if required for private repos | ||||||
|
|
||||||
| gts-spec-tests: | ||||||
| name: GTS Spec Tests | ||||||
| runs-on: ubuntu-latest | ||||||
| steps: | ||||||
| - name: Checkout | ||||||
| uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 | ||||||
| with: | ||||||
| persist-credentials: false | ||||||
|
|
||||||
| - name: Set up .NET | ||||||
| uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1 | ||||||
| with: | ||||||
| dotnet-version: '8.0.x' | ||||||
|
|
||||||
| # Builds the gts CLI binary, pulls the gts-spec test-runner image from | ||||||
| # GHCR (tag from .gts-spec-version), starts the server natively, waits | ||||||
| # for readiness, then runs pytest inside the container against | ||||||
| # host.docker.internal:$PORT. See Makefile. | ||||||
| - name: Run gts-spec tests via docker | ||||||
| run: make gts-spec-tests | ||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -17,4 +17,4 @@ internal static class GtsHttpJson | |
| { | ||
| PropertyNamingPolicy = JsonNamingPolicy.SnakeCaseLower | ||
| }; | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -134,4 +134,4 @@ private static JsonObject Resolve(JsonObject schema, Func<GtsId, JsonObject?> lo | |
| }; | ||
| return clone; | ||
| } | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -70,4 +70,4 @@ private static void CollectValues(JsonObject schema, JsonObject values) | |
| CollectValues(branch, values); | ||
| } | ||
| } | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -73,4 +73,4 @@ public override bool Validate(JsonElement value, out string? errorMessage) | |
| return valid; | ||
| } | ||
| } | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,4 @@ | ||
| using Gts.Parsing; | ||
| using Gts.Parsing; | ||
|
|
||
| namespace Gts.Tests.Parsing; | ||
|
|
||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -46,4 +46,4 @@ public void VersionFullParsesPartialVersionString() | |
| Assert.Equal(123, major); | ||
| Assert.Null(minor); | ||
| } | ||
| } | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
sed -n '1,145p' .github/workflows/ci.ymlRepository: GlobalTypeSystem/gts-dotnet
Length of output: 4098
🏁 Script executed:
Repository: GlobalTypeSystem/gts-dotnet
Length of output: 4605
🌐 Web query:
official GitHub actions/checkout persist-credentials default local git config pull_request fork GITHUB_TOKEN read-only permissions💡 Result:
Security Misconfiguration
Reachability: External
Exploitability: Difficult
CWE: CWE-522 — Insufficiently Protected Credentials
Disable credential persistence on all four
actions/checkoutsteps. Fork pull requests can supply untrusted project and test code to this workflow.actions/checkout@v4persists the read-onlyGITHUB_TOKENin.git/configby default, where that code can read and exfiltrate it. Setpersist-credentials: falseon every checkout step.Proposed fix
- name: Checkout uses: actions/checkout@v4 with: clean: 'true' + persist-credentials: falseApply the same setting to the other three checkout steps:
- name: Checkout uses: actions/checkout@v4 + with: + persist-credentials: false📝 Committable suggestion
🧰 Tools
🪛 zizmor (1.30.0)
[warning] 45-53: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
View in Security blast radius
🤖 Prompt for AI Agents