Skip to content

feat(hooks): CI annotations and SARIF upload for scanner findings #4

feat(hooks): CI annotations and SARIF upload for scanner findings

feat(hooks): CI annotations and SARIF upload for scanner findings #4

Workflow file for this run

name: Native CI
on:
pull_request:
types: [opened, synchronize, reopened]
workflow_dispatch:
permissions:
contents: read
pull-requests: write
security-events: write
statuses: write
env:
ATMOS_NATIVE_CI_WORKDIR: tests/fixtures/scenarios/native-ci-e2e
ATMOS_VERSION_CHECK_ENABLED: "false"
jobs:
terraform-plan:
name: "[native ci] terraform plan"
runs-on: ubuntu-latest
timeout-minutes: 20
services:
floci:
image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23
ports:
- 4566:4566
steps:
- name: Check out code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
with:
go-version-file: "go.mod"
- name: Build Atmos
run: |
make build-linux
echo "${{ github.workspace }}/build" >> "$GITHUB_PATH"
- name: Restore Atmos native CI cache
uses: ./actions/cache
env:
ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
- name: Validate native CI fixture
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos validate stacks
- name: Mirror Terraform providers
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json
- name: Terraform plan
id: terraform-plan
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
env:
ATMOS_CI_GITHUB_TOKEN: ${{ github.token }}
GITHUB_TOKEN: ${{ github.token }}
run: atmos terraform plan bucket -s test
terraform-apply:
name: "[native ci] terraform apply"
needs: terraform-plan
runs-on: ubuntu-latest
timeout-minutes: 20
services:
floci:
image: floci/floci@sha256:c88ec20bf221630dd195d38a14eeb0ac52ddfa72c37ebb3c8aa17f63ae27c5f2 # 1.5.23
ports:
- 4566:4566
steps:
- name: Check out code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6
with:
go-version-file: "go.mod"
- name: Build Atmos
run: |
make build-linux
echo "${{ github.workspace }}/build" >> "$GITHUB_PATH"
- name: Restore Atmos native CI cache
uses: ./actions/cache
env:
ATMOS_CHDIR: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
- name: Validate native CI fixture
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos validate stacks
- name: Mirror Terraform providers
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
run: atmos terraform cache mirror bucket -s test --platform=linux_amd64 --format=json
- name: Terraform apply
id: terraform-apply
working-directory: ${{ env.ATMOS_NATIVE_CI_WORKDIR }}
env:
ATMOS_CI_GITHUB_TOKEN: ${{ github.token }}
GITHUB_TOKEN: ${{ github.token }}
run: atmos terraform apply bucket -s test -auto-approve