Skip to content

CI

CI #171

Workflow file for this run

name: CI
on:
push:
branches:
- master
pull_request:
types:
- opened
- synchronize
- reopened
permissions:
contents: read
concurrency:
group: test-${{ github.ref }}
cancel-in-progress: true
jobs:
semantic-git-messages:
name: Commits
uses: ./.github/workflows/semantic-git-message.yml
php-code-style:
name: PHP Code Style
uses: ./.github/workflows/php-codestyle.yml
with:
app-name: activity
app-repository: owncloud/activity
php-versions: '["8.3"]'
php-code-style-no-phan:
name: PHP Code Style (--no-phan)
uses: ./.github/workflows/php-codestyle.yml
with:
app-name: activity
app-repository: owncloud/activity
php-versions: '["8.3"]'
disable-phan: true
php-code-style-additional-app:
name: PHP Code Style (+additional app)
uses: ./.github/workflows/php-codestyle.yml
with:
app-name: activity
app-repository: owncloud/activity
php-versions: '["8.3"]'
additional-app: customgroups
php-unit:
name: PHP Unit
uses: ./.github/workflows/php-unit.yml
with:
app-name: activity
app-repository: owncloud/activity
php-versions: '["8.3"]'
php-unit-ceph:
name: PHP Unit with Ceph S3
uses: ./.github/workflows/php-unit.yml
with:
app-name: files_primary_s3
app-repository: owncloud/files_primary_s3
php-versions: '["8.3"]'
use-ceph-s3: true
additional-packages: imagemagick
php-integration:
name: PHP Integration
uses: ./.github/workflows/php-unit.yml
with:
app-name: notes
app-repository: owncloud/notes
php-versions: '["8.3"]'
do-integration-tests: true
js-unit:
name: JS Unit
uses: ./.github/workflows/js-unit.yml
with:
app-name: customgroups
app-repository: owncloud/customgroups
php-version: '8.3'
additional-packages: exiftool bison
js-unit-xvfb-display:
name: JS Unit with Xvfb Display Server
uses: ./.github/workflows/js-unit.yml
with:
app-name: calendar
app-repository: owncloud/calendar
php-version: '8.3'
enable-xvfb-display-server: true
build-dist:
name: Build dist
uses: ./.github/workflows/build.yml
# Both trivy jobs scan a real app rather than this repository: `make dist` here
# produces only a .tar.gz, and Trivy does not look inside archives, so scanning
# this repo would pass without ever reading a file.
trivy:
name: Trivy
uses: ./.github/workflows/trivy.yml
with:
# No app-name on purpose. The app is checked out at the workspace root, so
# its Makefile's app_name=$(notdir $(CURDIR)) evaluates to this repository's
# name - which is exactly what app-name defaults to. Passing
# app-name: activity would look for build/dist/activity and fail.
app-repository: owncloud/activity
trivy-artifacts-layout:
name: Trivy (artifacts layout)
uses: ./.github/workflows/trivy.yml
with:
# announcementcenter uses the older build/artifacts/appstore/<app> tree, so
# this covers the second candidate of the scan path autodetection.
# php-version and node-version only exercise the optional setup steps; this
# app's dist target needs neither.
app-repository: owncloud/announcementcenter
php-version: '8.3'
node-version: '18'
gen-signing-key:
name: Generate throwaway signing key
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
key: ${{ steps.gen.outputs.key }}
cert: ${{ steps.gen.outputs.cert }}
steps:
# A self-signed, single-day EC P-384 leaf outside the ownCloud PKI. ocsign
# does not validate the chain up to a root, so this is enough to exercise
# the real signing path. CN must equal the app id under test.
- name: Generate key and certificate
id: gen
run: |
openssl ecparam -name secp384r1 -genkey -noout -out key.pem
openssl req -new -x509 -key key.pem -out cert.pem -subj "/CN=activity" -days 1
{
echo 'key<<EOF_KEY'
cat key.pem
echo 'EOF_KEY'
echo 'cert<<EOF_CERT'
cat cert.pem
echo 'EOF_CERT'
} >> "$GITHUB_OUTPUT"
release-dry-run:
name: Release (dry run)
needs: gen-signing-key
permissions:
contents: write
uses: ./.github/workflows/release.yml
with:
app-name: activity
app-repository: owncloud/activity
dry-run: true
secrets:
SIGNING_KEY: ${{ needs.gen-signing-key.outputs.key }}
SIGNING_CERT: ${{ needs.gen-signing-key.outputs.cert }}
calens:
name: Changelog
uses: ./.github/workflows/calens.yml
secrets:
APP_ID: ${{ secrets.CALENS_APP_ID }}
APP_PRIVATE_KEY: ${{ secrets.CALENS_APP_PRIVATE_KEY }}
acceptance-api:
name: API acceptance tests
uses: ./.github/workflows/acceptance.yml
with:
app-name: activity
app-repository: owncloud/activity
do-api-tests: true
acceptance-webui:
name: WebUI acceptance tests
uses: ./.github/workflows/acceptance.yml
with:
app-name: activity
app-repository: owncloud/activity
do-webui-tests: true
test-suites: "['webUIActivityComments', 'webUIActivityTags']"
acceptance-api-email:
name: API acceptance tests with Email Server
uses: ./.github/workflows/acceptance.yml
with:
app-name: notifications
app-repository: owncloud/notifications
do-api-tests: true
use-email-server: true
acceptance-webui-federated:
name: WebUI acceptance tests that need a federated server
uses: ./.github/workflows/acceptance.yml
with:
app-name: activity
app-repository: owncloud/activity
do-webui-tests: true
databases: '["mariadb:10.6", "postgres:10.21"]'
server-folder: 'server'
federated-folder: 'federated'
test-suites: "['webUIActivitySharingExternal']"
acceptance-api-elasticsearch:
name: API acceptance tests with Elasticsearch
uses: ./.github/workflows/acceptance.yml
with:
app-name: search_elastic
app-repository: owncloud/search_elastic
do-api-tests: true
filter-tags: '@smokeTest'
elasticsearch-version: '7.17'
test-suites: "['apiSearchElastic']"