kopia lustrzana https://github.com/kartoza/docker-postgis
Add scanning option (#472)
* Add a scanning option for vulnerabilities --------- Co-authored-by: spatialgeobyte <158478685+spatialgeobyte@users.noreply.github.com>pull/473/head
rodzic
0772eb3100
commit
98e2513bff
|
@ -3,4 +3,4 @@ updates:
|
||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
interval: "monthly"
|
interval: "weekly"
|
|
@ -4,12 +4,24 @@ on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches:
|
branches:
|
||||||
- develop
|
- develop
|
||||||
|
paths:
|
||||||
|
- 'Dockerfile'
|
||||||
|
- 'scripts/**'
|
||||||
|
- 'base_build/**'
|
||||||
|
- '.github/workflows/**'
|
||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- develop
|
- develop
|
||||||
|
paths:
|
||||||
|
- 'Dockerfile'
|
||||||
|
- 'scripts/**'
|
||||||
|
- 'build_data/**'
|
||||||
|
- '.github/workflows/**'
|
||||||
jobs:
|
jobs:
|
||||||
run-scenario-tests:
|
build-docker-image:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 25
|
||||||
|
if: github.actor != 'dependabot[bot]'
|
||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
postgresMajorVersion:
|
postgresMajorVersion:
|
||||||
|
@ -22,14 +34,6 @@ jobs:
|
||||||
- imageDistro: debian
|
- imageDistro: debian
|
||||||
imageDistroVersion: bookworm
|
imageDistroVersion: bookworm
|
||||||
imageDistroVariant: slim
|
imageDistroVariant: slim
|
||||||
scenario:
|
|
||||||
- datadir_init
|
|
||||||
- streaming_replication
|
|
||||||
- collations
|
|
||||||
- extensions
|
|
||||||
- logical_replication
|
|
||||||
- init_scripts
|
|
||||||
- multiple_databases
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- name: Set up QEMU
|
- name: Set up QEMU
|
||||||
|
@ -45,6 +49,7 @@ jobs:
|
||||||
push: false
|
push: false
|
||||||
load: true
|
load: true
|
||||||
tags: kartoza/postgis:manual-build
|
tags: kartoza/postgis:manual-build
|
||||||
|
outputs: type=docker,dest=/tmp/postgis.tar
|
||||||
build-args: |
|
build-args: |
|
||||||
DISTRO=${{ matrix.imageVersion.imageDistro }}
|
DISTRO=${{ matrix.imageVersion.imageDistro }}
|
||||||
IMAGE_VERSION=${{ matrix.imageVersion.imageDistroVersion }}
|
IMAGE_VERSION=${{ matrix.imageVersion.imageDistroVersion }}
|
||||||
|
@ -55,12 +60,42 @@ jobs:
|
||||||
POSTGIS_MAJOR_VERSION=${{ matrix.postgisMajorVersion }}
|
POSTGIS_MAJOR_VERSION=${{ matrix.postgisMajorVersion }}
|
||||||
POSTGIS_MINOR_VERSION=${{ matrix.postgisMinorRelease }}
|
POSTGIS_MINOR_VERSION=${{ matrix.postgisMinorRelease }}
|
||||||
cache-from: |
|
cache-from: |
|
||||||
type=gha,scope=test
|
type=gha,scope=test
|
||||||
type=gha,scope=prod
|
type=gha,scope=prod
|
||||||
type=gha,scope=base
|
type=gha,scope=base
|
||||||
cache-to: type=gha,scope=test
|
cache-to: type=gha,scope=test
|
||||||
target: postgis-test
|
target: postgis-test
|
||||||
|
- name: Upload artifact
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: kartoza-postgis
|
||||||
|
path: /tmp/postgis.tar
|
||||||
|
|
||||||
|
run-scenario-tests:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
needs: [build-docker-image]
|
||||||
|
timeout-minutes: 20
|
||||||
|
if: github.actor != 'dependabot[bot]'
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
scenario:
|
||||||
|
- datadir_init
|
||||||
|
- streaming_replication
|
||||||
|
- collations
|
||||||
|
- extensions
|
||||||
|
- logical_replication
|
||||||
|
- init_scripts
|
||||||
|
- multiple_databases
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: Download artifact
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: kartoza-postgis
|
||||||
|
path: /tmp
|
||||||
|
- name: Load image
|
||||||
|
run: |
|
||||||
|
docker load --input /tmp/postgis.tar
|
||||||
- name: Run scenario test ${{ matrix.scenario }}
|
- name: Run scenario test ${{ matrix.scenario }}
|
||||||
working-directory: scenario_tests/${{ matrix.scenario }}
|
working-directory: scenario_tests/${{ matrix.scenario }}
|
||||||
env:
|
env:
|
||||||
|
@ -68,29 +103,45 @@ jobs:
|
||||||
PRINT_TEST_LOGS: 1
|
PRINT_TEST_LOGS: 1
|
||||||
run: |
|
run: |
|
||||||
bash ./test.sh
|
bash ./test.sh
|
||||||
|
scan_image:
|
||||||
push-internal-pr-images:
|
|
||||||
if: github.event.pull_request.base.repo.url == github.event.pull_request.head.repo.url
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
needs: [ run-scenario-tests ]
|
timeout-minutes: 20
|
||||||
strategy:
|
if: github.actor != 'dependabot[bot]'
|
||||||
matrix:
|
needs: [build-docker-image, run-scenario-tests]
|
||||||
postgresMajorVersion:
|
|
||||||
- 16
|
|
||||||
postgisMajorVersion:
|
|
||||||
- 3
|
|
||||||
postgisMinorRelease:
|
|
||||||
- 4
|
|
||||||
imageVersion:
|
|
||||||
- imageDistro: debian
|
|
||||||
imageDistroVersion: bookworm
|
|
||||||
imageDistroVariant: slim
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- name: Set up QEMU
|
- name: Download artifact
|
||||||
uses: docker/setup-qemu-action@v3
|
uses: actions/download-artifact@v4
|
||||||
- name: Set up Docker Buildx
|
with:
|
||||||
uses: docker/setup-buildx-action@v3
|
name: kartoza-postgis
|
||||||
|
path: /tmp
|
||||||
|
- name: Load image
|
||||||
|
run: |
|
||||||
|
docker load --input /tmp/postgis.tar
|
||||||
|
- name: Run Trivy vulnerability scanner
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
format: 'sarif'
|
||||||
|
ignore-unfixed: true
|
||||||
|
image-ref: kartoza/postgis:manual-build
|
||||||
|
output: 'trivy-results.sarif'
|
||||||
|
severity: 'CRITICAL,HIGH'
|
||||||
|
vuln-type: 'os,library'
|
||||||
|
|
||||||
|
push-internal-pr-images:
|
||||||
|
if: github.event.pull_request.base.repo.url == github.event.pull_request.head.repo.url && github.actor != 'dependabot[bot]'
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
needs: [ build-docker-image, run-scenario-tests ]
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: Download artifact
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: kartoza-postgis
|
||||||
|
path: /tmp
|
||||||
|
- name: Load image
|
||||||
|
run: |
|
||||||
|
docker load --input /tmp/postgis.tar
|
||||||
- name: Login to DockerHub
|
- name: Login to DockerHub
|
||||||
uses: docker/login-action@v3
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
|
@ -102,31 +153,7 @@ jobs:
|
||||||
with:
|
with:
|
||||||
images: ${{ secrets.DOCKERHUB_REPO}}/postgis
|
images: ${{ secrets.DOCKERHUB_REPO}}/postgis
|
||||||
tags: |
|
tags: |
|
||||||
type=semver,pattern={{version}}
|
type=semver,pattern=\d.\d.\d
|
||||||
type=ref,event=branch
|
type=ref,event=branch
|
||||||
type=ref,event=pr
|
|
||||||
|
|
||||||
- name: Build image for testing
|
|
||||||
id: docker_build_testing_image
|
|
||||||
uses: docker/build-push-action@v5
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
file: Dockerfile
|
|
||||||
push: true
|
|
||||||
tags: |
|
|
||||||
${{ steps.docker_meta.outputs.tags }}-${{ matrix.postgresMajorVersion }}-${{ matrix.postgisMajorVersion }}.${{ matrix.postgisMinorRelease }}
|
|
||||||
build-args: |
|
|
||||||
DISTRO=${{ matrix.imageVersion.imageDistro }}
|
|
||||||
IMAGE_VERSION=${{ matrix.imageVersion.imageDistroVersion }}
|
|
||||||
IMAGE_VARIANT=${{ matrix.imageVersion.imageDistroVariant }}
|
|
||||||
LANGS=en_US.UTF-8,id_ID.UTF-8
|
|
||||||
GENERATE_ALL_LOCALE=0
|
|
||||||
POSTGRES_MAJOR_VERSION=${{ matrix.postgresMajorVersion }}
|
|
||||||
POSTGIS_MAJOR_VERSION=${{ matrix.postgisMajorVersion }}
|
|
||||||
POSTGIS_MINOR_VERSION=${{ matrix.postgisMinorRelease }}
|
|
||||||
cache-from: |
|
|
||||||
type=gha,scope=test
|
|
||||||
type=gha,scope=prod
|
|
||||||
type=gha,scope=base
|
|
||||||
cache-to: type=gha,scope=test
|
|
||||||
target: postgis-test
|
|
||||||
|
|
|
@ -11,6 +11,8 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
deploy-image:
|
deploy-image:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 20
|
||||||
|
if: github.actor != 'dependabot[bot]'
|
||||||
env:
|
env:
|
||||||
latest-ref: refs/heads/develop
|
latest-ref: refs/heads/develop
|
||||||
strategy:
|
strategy:
|
||||||
|
@ -37,14 +39,11 @@ jobs:
|
||||||
with:
|
with:
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
password: ${{ secrets.DOCKERHUB_PASSWORD }}
|
||||||
|
|
||||||
- name: Get Current Date
|
- name: Get Current Date
|
||||||
id: current_date
|
id: current_date
|
||||||
shell: python
|
shell: python
|
||||||
run: |
|
run: echo "formatted=$(date -u +%Y.%m.%d)" >> $GITHUB_OUTPUT
|
||||||
import datetime
|
|
||||||
now = datetime.datetime.utcnow()
|
|
||||||
print(f'::set-output name=formatted::{now:%Y.%m.%d}')
|
|
||||||
|
|
||||||
- name: Build base image
|
- name: Build base image
|
||||||
id: docker_build_base
|
id: docker_build_base
|
||||||
|
|
Ładowanie…
Reference in New Issue