fix(deps): update github.com/google/go-containerregistry/pkg/authn/k8schain digest to 8a72a42 (main) #2541
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - release-* | |
| pull_request: {} | |
| workflow_dispatch: {} | |
| env: | |
| # We can't run a step 'if secrets.FOO != ""' but we can run a step | |
| # 'if env.FOO' != ""', so we copy secrets to env vars for conditional checks. | |
| DOCKER_USR: ${{ secrets.DOCKER_USR }} | |
| jobs: | |
| check-diff: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Install Nix | |
| uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31 | |
| - name: Setup Cachix | |
| uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: crossplane | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Verify Generated Code | |
| run: nix build .#checks.x86_64-linux.generate --print-build-logs | |
| validate-renovate-config: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| # renovate-config-validator only looks at the top-level file and does | |
| # not recursively resolve local> presets, so we also syntax-check every | |
| # renovate*.json5 with the json5 CLI to catch preset parse errors at | |
| # PR time rather than 24h later in the scheduled Renovate job. | |
| - name: Validate Renovate preset syntax | |
| run: | | |
| for f in .github/renovate*.json5; do | |
| npx --yes json5 "$f" > /dev/null | |
| done | |
| - name: Validate Renovate JSON | |
| run: npx --yes --package renovate -- renovate-config-validator | |
| lint: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Install Nix | |
| uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31 | |
| - name: Setup Cachix | |
| uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: crossplane | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Lint | |
| run: nix build .#checks.x86_64-linux.go-lint --print-build-logs | |
| codeql: | |
| runs-on: ubuntu-24.04 | |
| permissions: | |
| contents: read | |
| security-events: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Install Nix | |
| uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31 | |
| - name: Setup Cachix | |
| uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: crossplane | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Setup Nix Environment | |
| uses: nicknovitski/nix-develop@9be7cfb4b10451d3390a75dc18ad0465bed4932a # v1 | |
| - name: Initialize CodeQL | |
| uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 | |
| with: | |
| languages: go | |
| - name: Perform CodeQL Analysis | |
| uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4 | |
| unit-tests: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Install Nix | |
| uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31 | |
| - name: Setup Cachix | |
| uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: crossplane | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Run Unit Tests | |
| run: nix build .#checks.x86_64-linux.test --print-build-logs | |
| - name: Publish Unit Test Coverage | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7 | |
| with: | |
| flags: unittests | |
| file: result/coverage.txt | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| protobuf-schemas: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Setup Buf | |
| uses: bufbuild/buf-setup-action@v1 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Lint Protocol Buffers | |
| uses: bufbuild/buf-lint-action@v1 | |
| # buf-breaking-action doesn't support branches | |
| # https://github.com/bufbuild/buf-push-action/issues/34 | |
| - name: Detect Breaking Changes in Protocol Buffers | |
| uses: bufbuild/buf-breaking-action@a074e988ee34efcd4927079e79c611f428354c01 # v1 | |
| # We want to run this for the main branch, and PRs against main. | |
| if: ${{ github.ref == 'refs/heads/main' || github.base_ref == 'main' }} | |
| with: | |
| against: "https://github.com/${GITHUB_REPOSITORY}.git#branch=main" | |
| - name: Push Protocol Buffers to Buf Schema Registry | |
| if: ${{ github.repository == 'crossplane/crossplane-runtime' && github.ref == 'refs/heads/main' }} | |
| uses: bufbuild/buf-push-action@v1 | |
| with: | |
| buf_token: ${{ secrets.BUF_TOKEN }} |