name: CI/CD Pipeline on: push: branches: [ main, develop ] pull_request: branches: [ main, develop ] jobs: test: name: Test & Lint runs-on: ubuntu-latest services: mariadb: image: mariadb:11.0-alpine env: MYSQL_ROOT_PASSWORD: root MYSQL_DATABASE: blogging_cms MYSQL_USER: cms_user MYSQL_PASSWORD: cms_password options: >- --health-cmd="healthcheck.sh --connect" --health-interval=10s --health-timeout=5s --health-retries=3 ports: - 3306:3306 steps: - name: Checkout code uses: actions/checkout@v3 - name: Set up Go uses: actions/setup-go@v4 with: go-version: '1.21' - name: Cache Go modules uses: actions/cache@v3 with: path: ~/go/pkg/mod key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }} restore-keys: | ${{ runner.os }}-go- - name: Download dependencies run: go mod download - name: Format check run: | if [ "$(gofmt -s -l . | wc -l)" -gt 0 ]; then echo "Code formatting issues found:" gofmt -s -d . exit 1 fi - name: Vet run: go vet ./... - name: Run tests env: DB_HOST: localhost DB_PORT: 3306 DB_USER: cms_user DB_PASSWORD: cms_password DB_NAME: blogging_cms run: go test -v -race -coverprofile=coverage.out ./... - name: Upload coverage uses: codecov/codecov-action@v3 with: file: ./coverage.out flags: unittests name: codecov-umbrella build: name: Build Docker Image runs-on: ubuntu-latest needs: test if: github.event_name == 'push' && github.ref == 'refs/heads/main' permissions: contents: read packages: write steps: - name: Checkout code uses: actions/checkout@v3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v2 - name: Login to GitHub Container Registry uses: docker/login-action@v2 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Build and push Docker image uses: docker/build-push-action@v4 with: context: . push: true tags: | ghcr.io/${{ github.repository }}:latest ghcr.io/${{ github.repository }}:${{ github.sha }} cache-from: type=registry,ref=ghcr.io/${{ github.repository }}:buildcache cache-to: type=registry,ref=ghcr.io/${{ github.repository }}:buildcache,mode=max security: name: Security Scan runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v3 - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: scan-type: 'fs' scan-ref: '.' format: 'sarif' output: 'trivy-results.sarif' - name: Upload Trivy results to GitHub Security tab uses: github/codeql-action/upload-sarif@v2 with: sarif_file: 'trivy-results.sarif'