Skip to content

SDLe fix: Github workflow vulnerabilities and migration to github runner #27

SDLe fix: Github workflow vulnerabilities and migration to github runner

SDLe fix: Github workflow vulnerabilities and migration to github runner #27

Workflow file for this run

#
# BSD 3-Clause License
# Copyright (C) 2026 Intel Corporation
# SPDX-License-Identifier: BSD-3-Clause
#
name: Continuous Integration
on:
push:
branches:
- main
pull_request:
branches:
- main
workflow_dispatch:
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
ci:
name: Continuous Integration
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Clean up previous run
env:
WORKSPACE: ${{ github.workspace }}
run: |
find "$WORKSPACE" -mindepth 1 -maxdepth 1 -exec rm -rf {} +
rm -rf /tmp/trivy-*
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false
- name: Environment check
uses: ./.github/actions/environment-check
- name: Build dvledtx
uses: ./.github/actions/build-dvledtx
- name: Smoke test
uses: ./.github/actions/smoke-tests
- name: Run unit tests
uses: ./.github/actions/unit-tests
- name: ShellCheck
uses: ./.github/actions/analysis/shellcheck
- name: cppcheck
uses: ./.github/actions/analysis/cppcheck
- name: Coverity Scan
uses: ./.github/actions/analysis/coverity
with:
coverity-url: ${{ secrets.COVERITY_URL }}
coverity-user: ${{ secrets.COVERITY_ARTIFACTORY_USER }}
coverity-password: ${{ secrets.COVERITY_ARTIFACTORY_PASSWORD }}
- name: Trivy Scan
uses: ./.github/actions/analysis/trivy
- name: Upload all reports
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: always()
with:
name: all-scan-reports-${{ github.run_id }}
path: ${{ env.GITHUB_WORKSPACE }}/reports/
retention-days: 30