diff --git a/.github/workflows/dockerbuild.yaml b/.github/workflows/dockerbuild.yaml index 570c21f1..7b719644 100644 --- a/.github/workflows/dockerbuild.yaml +++ b/.github/workflows/dockerbuild.yaml @@ -20,19 +20,19 @@ jobs: include: - app: frontend path: frontend - version: latest + version: 2.0.2 experimental: true - app: backend path: backend - version: latest + version: 2.0.2 experimental: true - app: orborus path: functions/onprem/orborus - version: latest + version: 2.0.2 experimental: true - app: worker path: functions/onprem/worker - version: latest + version: 2.0.2 experimental: true steps: - name: Checkout diff --git a/.github/workflows/nightly-release.yaml b/.github/workflows/nightly-release.yaml deleted file mode 100644 index b66f9559..00000000 --- a/.github/workflows/nightly-release.yaml +++ /dev/null @@ -1,83 +0,0 @@ -name: Nightly Release -on: - release: - types: [published] - branches: - - main - - nightly - -jobs: - main: - runs-on: ubuntu-latest - continue-on-error: ${{ matrix.experimental }} - strategy: - fail-fast: false - matrix: - include: - - app: frontend - path: frontend - experimental: true - - app: backend - path: backend - experimental: true - - app: orborus - path: functions/onprem/orborus - experimental: true - - app: worker - path: functions/onprem/worker - experimental: true - steps: - - name: Checkout - uses: actions/checkout@v3 - - - name: Set version - id: set_version - run: | - if [[ ${{ github.event_name }} == 'release' ]]; then - echo "VERSION=${{ github.event.release.tag_name }}" >> $GITHUB_OUTPUT - else - echo "VERSION=nightly-untagged-latest" >> $GITHUB_OUTPUT - fi - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Set up QEMU - uses: docker/setup-qemu-action@v3 - with: - platforms: "amd64,arm64,arm" - - - name: Login to DockerHub - uses: docker/login-action@v3 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - - - name: Login to Ghcr - uses: docker/login-action@v3 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Ghcr Build and push - id: docker_build - uses: docker/build-push-action@v4 - env: - BUILDX_NO_DEFAULT_LOAD: true - with: - logout: false - context: ${{ matrix.path }}/ - file: ${{ matrix.path }}/Dockerfile - platforms: linux/amd64,linux/arm64 - push: true - cache-from: type=local,src=/tmp/.buildx-cache - cache-to: type=local,dest=/tmp/.buildx-cache - tags: | - ghcr.io/shuffle/shuffle-${{ matrix.app }}:${{ steps.set_version.outputs.VERSION }} - ${{ secrets.DOCKERHUB_USERNAME }}/shuffle-${{ matrix.app }}:${{ steps.set_version.outputs.VERSION }} - frikky/shuffle-${{ matrix.app }}:${{ steps.set_version.outputs.VERSION }} - frikky/shuffle:${{ matrix.app }} - - - name: Image digest - run: echo ${{ steps.docker_build.outputs.digest }} \ No newline at end of file diff --git a/.github/workflows/project_automation.yml b/.github/workflows/project_automation.yml deleted file mode 100644 index 0e3bf945..00000000 --- a/.github/workflows/project_automation.yml +++ /dev/null @@ -1,16 +0,0 @@ -name: Automation - Add all new issues to roadmap project - -on: - issues: - types: - - opened - -jobs: - add-to-project: - name: Add issue to project - runs-on: ubuntu-latest - steps: - - uses: actions/add-to-project@v0.5.0 - with: - project-url: https://github.com/orgs/Shuffle/projects/8 - github-token: ${{ secrets.ADD_TO_PROJECT_PAT }} diff --git a/.github/workflows/snyk-container-analysis.yml b/.github/workflows/snyk-container-analysis.yml deleted file mode 100755 index f9a406b2..00000000 --- a/.github/workflows/snyk-container-analysis.yml +++ /dev/null @@ -1,50 +0,0 @@ -# A sample workflow which checks out the code, builds a container -# image using Docker and scans that image for vulnerabilities using -# Snyk. The results are then uploaded to GitHub Security Code Scanning -# -# For more examples, including how to limit scans to only high-severity -# issues, monitor images for newly disclosed vulnerabilities in Snyk and -# fail PR checks for new vulnerabilities, see https://github.com/snyk/actions/ - -name: Snyk Container - -on: - push: - branches: - - launch - pull_request: - # The branches below must be a subset of the branches above - branches: - - master - - launch - schedule: - - cron: '18 4 * * 3' - -jobs: - snyk: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v2 - - - name: Build a Docker image - run: docker build -t frontend . - - - name: Run Snyk to check Docker image for vulnerabilities - # Snyk can be used to break the build when it detects vulnerabilities. - # In this case we want to upload the issues to GitHub Code Scanning - continue-on-error: true - uses: snyk/actions/docker@master - env: - # In order to use the Snyk Action you will need to have a Snyk API token. - # More details in https://github.com/snyk/actions#getting-your-snyk-token - # or you can signup for free at https://snyk.io/login - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - with: - image: your/image-to-test - args: --file=Dockerfile - - - name: Upload result to GitHub Code Scanning - uses: github/codeql-action/upload-sarif@v1 - with: - sarif_file: snyk.sarif diff --git a/.github/workflows/snyk-infrastructure-analysis.yml b/.github/workflows/snyk-infrastructure-analysis.yml deleted file mode 100755 index 4402487d..00000000 --- a/.github/workflows/snyk-infrastructure-analysis.yml +++ /dev/null @@ -1,46 +0,0 @@ -# A sample workflow which checks out your Infrastructure as Code Configuration files, -# such as Kubernetes, Helm & Terraform and scans them for any security issues. -# The results are then uploaded to GitHub Security Code Scanning -# -# For more examples, including how to limit scans to only high-severity issues -# and fail PR checks, see https://github.com/snyk/actions/ - -name: Snyk Infrastructure as Code - -on: - push: - branches: - - master - - launch - pull_request: - # The branches below must be a subset of the branches above - branches: - - master - - launch - schedule: - - cron: '41 16 * * 2' - -jobs: - snyk: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v2 - - name: Run Snyk to check configuration files for security issues - # Snyk can be used to break the build when it detects security issues. - # In this case we want to upload the issues to GitHub Code Scanning - continue-on-error: true - uses: snyk/actions/iac@master - env: - # In order to use the Snyk Action you will need to have a Snyk API token. - # More details in https://github.com/snyk/actions#getting-your-snyk-token - # or you can signup for free at https://snyk.io/login - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - with: - # Add the path to the configuration file that you would like to test. - # For example `deployment.yaml` for a Kubernetes deployment manifest - # or `main.tf` for a Terraform configuration file - file: your-file-to-test.yaml - - name: Upload result to GitHub Code Scanning - uses: github/codeql-action/upload-sarif@v1 - with: - sarif_file: snyk.sarif