ci: bump docker/build-push-action from 5 to 6 #4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # .github/workflows/ci.yml | |
| # Prometheus Banking Platform - Continuous Integration Pipeline | |
| # Triggers on push to main/develop and PRs to main | |
| name: CI | |
| on: | |
| push: | |
| branches: [main, develop] | |
| pull_request: | |
| branches: [main] | |
| env: | |
| JAVA_VERSION: '21' | |
| REGISTRY: ghcr.io | |
| IMAGE_NAME: ${{ github.repository }}/prometheus-app | |
| jobs: | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| # BUILD & TEST | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| build: | |
| name: Build & Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up JDK 21 | |
| uses: actions/setup-java@v4 | |
| with: | |
| java-version: ${{ env.JAVA_VERSION }} | |
| distribution: 'temurin' | |
| cache: gradle | |
| - name: Grant execute permission for gradlew | |
| run: | | |
| if [ -d "services" ]; then | |
| find services -name "gradlew" -exec chmod +x {} \; | |
| fi | |
| - name: Build all services | |
| run: | | |
| echo "Build step - services not yet created" | |
| # cd services/account-service && ./gradlew build -x test | |
| # cd services/transaction-service && ./gradlew build -x test | |
| # cd services/api-gateway && ./gradlew build -x test | |
| - name: Run Unit Tests | |
| run: | | |
| echo "Unit tests - services not yet created" | |
| # cd services/account-service && ./gradlew test | |
| - name: Run Integration Tests | |
| run: | | |
| echo "Integration tests - services not yet created" | |
| # cd services/account-service && ./gradlew integrationTest | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| # SECURITY SCANNING | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| security-scan: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| needs: build | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Run Trivy vulnerability scanner (filesystem) | |
| uses: aquasecurity/trivy-action@master | |
| with: | |
| scan-type: 'fs' | |
| scan-ref: '.' | |
| format: 'table' | |
| exit-code: '0' # Don't fail on vulnerabilities for now | |
| severity: 'CRITICAL,HIGH' | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| # KUBERNETES MANIFEST SCANNING | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| kubescape-scan: | |
| name: Kubernetes Security Scan | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Kubescape scan | |
| uses: kubescape/github-action@main | |
| with: | |
| files: "k8s/" | |
| framework: nsa | |
| format: sarif | |
| outputFile: kubescape-results.sarif | |
| continue-on-error: true # Don't fail build on security warnings | |
| - name: Upload Kubescape results | |
| uses: github/codeql-action/upload-sarif@v3 | |
| if: always() | |
| with: | |
| sarif_file: kubescape-results.sarif | |
| continue-on-error: true | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| # DOCKER BUILD & PUSH (only on main branch) | |
| # ═══════════════════════════════════════════════════════════════════════════ | |
| push-image: | |
| name: Build & Push Docker Image | |
| runs-on: ubuntu-latest | |
| needs: [build, security-scan] | |
| if: github.ref == 'refs/heads/main' && github.event_name == 'push' | |
| permissions: | |
| contents: read | |
| packages: write | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Extract metadata for Docker | |
| id: meta | |
| uses: docker/metadata-action@v5 | |
| with: | |
| images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} | |
| tags: | | |
| type=sha,prefix= | |
| type=raw,value=latest | |
| - name: Build and push Docker image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: ./services | |
| file: ./services/Dockerfile.dev.template | |
| push: false # Set to true when services are ready | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max |