mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
12 hours ago 1a090f1d26d5c7ed693992735ac29eae7dd3ee8d
.github/workflows/build.yml
@@ -24,7 +24,8 @@
  cancel-in-progress: true
# Nothing in this workflow writes back to the repository: the docker jobs push to
# the local registry service, not to a remote one.
# the local registry service, not to a remote one. The docker jobs additionally get
# security-events: write to upload Trivy scan results to code scanning.
permissions:
  contents: read
@@ -393,6 +394,9 @@
  build-docker:
    needs: build-maven
    runs-on: 'ubuntu-latest'
    permissions:
      contents: read
      security-events: write
    services:
      registry:
        image: registry:3
@@ -411,6 +415,7 @@
        run:   |
          export git_version_last="$(curl -i -o - --silent https://api.github.com/repos/OpenIdentityPlatform/OpenDJ/releases/latest | grep -m1 "\"name\"" | cut -d\" -f4)" ; echo "last release: $git_version_last"
          echo "release_version=$git_version_last" >> $GITHUB_ENV
          echo "image_repository=${GITHUB_REPOSITORY,,}" >> $GITHUB_ENV
      - name: Docker meta
        id: meta
        uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
@@ -465,6 +470,28 @@
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_custom | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_custom 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword custom_password --useSsl --trustAll --baseDN "dc=example,dc=com" --searchScope base "(objectClass=*)" 1.1'
          docker kill test_custom
      - name: Scan image for vulnerabilities (Trivy)
        # trivy resolves the image from the local Docker daemon, so only the runner's
        # linux/amd64 manifest is scanned; cache: false keeps the ~1GB trivy DBs from
        # evicting the m2-repository caches out of the repo's 10GB actions-cache quota
        uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
        with:
          image-ref: localhost:5000/${{ env.image_repository }}:${{ env.release_version }}
          format: sarif
          output: trivy-results.sarif
          severity: CRITICAL,HIGH
          limit-severities-for-sarif: true
          ignore-unfixed: true
          scanners: vuln
          cache: false
      - name: Upload Trivy report to GitHub Security
        uses: github/codeql-action/upload-sarif@v4
        # upload even if a preceding step failed, but not without a report to upload
        if: ${{ always() && hashFiles('trivy-results.sarif') != '' }}
        with:
          sarif_file: trivy-results.sarif
          # distinct from the docker-scan.yml categories, which track the published images
          category: trivy-build-default
      - name: Cache JMeter
        uses: actions/cache@v5
        with:
@@ -512,6 +539,9 @@
  build-docker-alpine:
    needs: build-maven
    runs-on: 'ubuntu-latest'
    permissions:
      contents: read
      security-events: write
    services:
      registry:
        image: registry:3
@@ -530,6 +560,7 @@
        run:   |
          export git_version_last="$(curl -i -o - --silent https://api.github.com/repos/OpenIdentityPlatform/OpenDJ/releases/latest | grep -m1 "\"name\"" | cut -d\" -f4)" ; echo "last release: $git_version_last"
          echo "release_version=$git_version_last" >> $GITHUB_ENV
          echo "image_repository=${GITHUB_REPOSITORY,,}" >> $GITHUB_ENV
      - name: Docker meta 
        id: meta
        uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
@@ -585,6 +616,28 @@
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_custom | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_custom 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword custom_password --useSsl --trustAll --baseDN "dc=example,dc=com" --searchScope base "(objectClass=*)" 1.1'
          docker kill test_custom
      - name: Scan image for vulnerabilities (Trivy)
        # trivy resolves the image from the local Docker daemon, so only the runner's
        # linux/amd64 manifest is scanned; cache: false keeps the ~1GB trivy DBs from
        # evicting the m2-repository caches out of the repo's 10GB actions-cache quota
        uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
        with:
          image-ref: localhost:5000/${{ env.image_repository }}:${{ env.release_version }}-alpine
          format: sarif
          output: trivy-results.sarif
          severity: CRITICAL,HIGH
          limit-severities-for-sarif: true
          ignore-unfixed: true
          scanners: vuln
          cache: false
      - name: Upload Trivy report to GitHub Security
        uses: github/codeql-action/upload-sarif@v4
        # upload even if a preceding step failed, but not without a report to upload
        if: ${{ always() && hashFiles('trivy-results.sarif') != '' }}
        with:
          sarif_file: trivy-results.sarif
          # distinct from the docker-scan.yml categories, which track the published images
          category: trivy-build-alpine
      - name: Cache JMeter
        uses: actions/cache@v5
        with: