name: ci on: push: branches: [main] tags: ['v*'] pull_request: permissions: contents: read jobs: test: runs-on: ubuntu-latest services: postgres: image: postgres:16-alpine env: POSTGRES_USER: aigw POSTGRES_PASSWORD: integration-only POSTGRES_DB: aigw_test ports: ['5432:5432'] options: >- --health-cmd "pg_isready -U aigw -d aigw_test" --health-interval 5s --health-timeout 3s --health-retries 20 redis: image: redis:7-alpine ports: ['6379:6379'] options: >- --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 3s --health-retries 20 env: AIGW_TEST_DATABASE_URL: postgres://aigw:integration-only@127.0.0.1:5432/aigw_test?sslmode=disable steps: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: go-version-file: go.mod cache: true - run: go test -count=1 -p=1 ./... - run: go test -race -count=1 -p=1 ./... - run: go vet ./... - run: CGO_ENABLED=0 go build -buildvcs=false -trimpath ./cmd/... image: needs: test runs-on: ubuntu-latest permissions: contents: read packages: write id-token: write steps: - uses: actions/checkout@v4 - uses: docker/setup-buildx-action@v3 - uses: docker/build-push-action@v6 with: context: . load: true tags: aigw:${{ github.sha }} - uses: anchore/sbom-action@v0 with: image: aigw:${{ github.sha }} format: spdx-json output-file: sbom.spdx.json - uses: actions/upload-artifact@v4 with: name: sbom-spdx path: sbom.spdx.json - uses: aquasecurity/trivy-action@0.28.0 with: image-ref: aigw:${{ github.sha }} format: table exit-code: '1' ignore-unfixed: true severity: HIGH,CRITICAL - uses: docker/login-action@v3 if: startsWith(github.ref, 'refs/tags/v') with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - id: publish uses: docker/build-push-action@v6 if: startsWith(github.ref, 'refs/tags/v') with: context: . push: true tags: ghcr.io/${{ github.repository }}:${{ github.ref_name }} - uses: sigstore/cosign-installer@v3 if: startsWith(github.ref, 'refs/tags/v') - name: Sign image by digest if: startsWith(github.ref, 'refs/tags/v') env: IMAGE: ghcr.io/${{ github.repository }} DIGEST: ${{ steps.publish.outputs.digest }} run: cosign sign --yes "$IMAGE@$DIGEST"