-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathMakefile
67 lines (53 loc) · 1.94 KB
/
Makefile
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
.PHONY: all
all: test docker-build scan-image ## Run all targets.
.PHONY: fmt
fmt: ## Run go fmt against code.
go fmt ./...
echo "Completed go fmt."
.PHONY: vet
vet: ## Run go vet against code.
go vet ./...
echo "Completed go vet."
.PHONY: lint
lint: ## Run hadolint against Dockerfile.
/bin/sh -c "hadolint -f sarif Dockerfile > release/evidence/hadolint.sarif"
echo "Completed scan for non-root software with hadolint."
.PHONY: sast
sast: ## Scan code with Semgrep.
semgrep scan --config auto ./ --sarif -o release/evidence/semgrep.sarif
echo "Completed static analysis with Semgrep."
.PHONY: test
test: ## Run tests.
go test ./... -coverprofile release/evidence/cover.out
echo "Completed unit tests."
.PHONY: build
build: ## Local go build.
go build -o bin/software main.go
.PHONY: docker-build
docker-build: ## Build docker image.
/bin/sh -c "docker build -t jkjell/software:dev . && docker save jkjell/software:dev > release/delivery/image.tar"
echo "Completed docker build."
.PHONY: scan-image
scan-image: generate-sbom cve-scan secret-scan ## Scan image.
.PHONY: generate-sbom
generate-sbom: ## Generate SBOM with Syft.
syft packages docker-archive:./release/delivery/image.tar -o spdx-json --file release/evidence/syft.spdx.json
echo "Completed generating SBOM with Syft."
.PHONY: cve-scan
cve-scan: ## Scan image for CVEs with Grype.
grype docker-archive:./release/delivery/image.tar -o sarif --file release/evidence/grype.sarif
echo "Completed cve scan with Grype."
.PHONY: secret-scan
secret-scan: ## Scan image for secrets with Trufflehog.
/bin/sh -c "trufflehog docker --image=file://release/delivery/image.tar -j > release/evidence/trufflehog.json"
echo "Completed secret scan with Trufflehog."
.PHONY: release
release: ## Create a release.
tar -czvf release.tar.gz release
.PHONY: clean
clean: ## Remove generated files.
rm -rf bin
rm -rf release/evidence/*
rm -rf release/attestations/*
rm -rf release/delivery/*
rm release.tar.gz