Bump github/codeql-action from 3.27.6 to 3.27.9 #901
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Checks | |
on: | |
push: | |
branches: | |
- main | |
pull_request: | |
branches: | |
- main | |
permissions: | |
contents: read | |
jobs: | |
Checks: | |
runs-on: ubuntu-latest | |
steps: | |
- name: Harden Runner | |
uses: step-security/harden-runner@0080882f6c36860b6ba35c610c98ce87d4e2f26f # v2.10.2 | |
with: | |
egress-policy: audit | |
disable-telemetry: true | |
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
- name: Setup Go environment | |
uses: actions/setup-go@41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed # v5.1.0 | |
with: | |
cache: true | |
go-version-file: go.mod | |
cache-dependency-path: '**/go.sum' | |
- name: Check go versions | |
uses: enterprise-contract/github-workflows/golang-version-check@main | |
- name: Test | |
run: make test | |
- name: Upload unit test coverage report | |
uses: codecov/codecov-action@7f8b4b4bde536c465e797be725718b88c5d95e0e # v5.1.1 | |
env: | |
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
with: | |
files: ./cover.out | |
flags: controller | |
- name: Upload api test coverage report | |
uses: codecov/codecov-action@7f8b4b4bde536c465e797be725718b88c5d95e0e # v5.1.1 | |
env: | |
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
with: | |
files: ./api_cover.out | |
flags: api | |
- name: Upload schema test coverage report | |
uses: codecov/codecov-action@7f8b4b4bde536c465e797be725718b88c5d95e0e # v5.1.1 | |
env: | |
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
with: | |
files: ./schema_cover.out | |
flags: schema | |
# If enterprisecontractpolicy_types.go is updated without a corresponding change to the crd | |
# an uncommitted change can show. | |
- name: Check for uncommitted changes | |
run: | | |
if ! git diff --exit-code -s; then | |
for f in $(git diff --exit-code --name-only); do | |
echo "::error file=$f,line=1,col=1,endColumn=1::File was modified in build" | |
done | |
exit 1 | |
fi |