Skip to content

Bump github/codeql-action from 4.32.4 to 4.35.1 #383

Bump github/codeql-action from 4.32.4 to 4.35.1

Bump github/codeql-action from 4.32.4 to 4.35.1 #383

Workflow file for this run

name: CI
on: [push, pull_request]
permissions:
contents: read
jobs:
test:
name: Test
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Install OTP and Elixir
uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.20.4
with:
otp-version: 27.2
elixir-version: 1.18.1
- name: Install dependencies
run: |
mix deps.get
mix deps.compile
- name: Check mix format
run: mix format --check-formatted
- name: Start Typesense
run: docker compose up -d typesense
- name: Run tests
run: |
mix test.all
docker:
name: Docker (${{ matrix.platform }})
runs-on: ${{ matrix.runner }}
permissions:
contents: "read"
id-token: "write"
strategy:
matrix:
include:
- platform: linux/amd64
runner: ubuntu-24.04
- platform: linux/arm64
runner: ubuntu-24.04-arm
env:
IMAGE_NAME: "hexdocs"
PROJECT_ID: "hexpm-prod"
SERVICE_ACCOUNT: ${{ secrets.GCLOUD_SERVICE_ACCOUNT }}
WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCLOUD_WORKFLOW_IDENTITY_POOL_PROVIDER }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Google auth
id: auth
uses: "google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093" # v3.0.0
if: ${{ github.event_name != 'pull_request' && env.SERVICE_ACCOUNT != '' }}
with:
token_format: "access_token"
project_id: ${{ env.PROJECT_ID }}
service_account: ${{ env.SERVICE_ACCOUNT }}
workload_identity_provider: ${{ env.WORKLOAD_IDENTITY_PROVIDER }}
- name: Docker Auth
id: docker-auth
uses: "docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2" # v4.0.0
if: ${{ github.event_name != 'pull_request' && env.SERVICE_ACCOUNT != '' }}
with:
registry: gcr.io
username: "oauth2accesstoken"
password: "${{ steps.auth.outputs.access_token }}"
- name: Build and push by digest
id: build
uses: docker/build-push-action@d08e5c354a6adb9ed34480a06d141179aa583294 # v7.0.0
with:
platforms: ${{ matrix.platform }}
outputs: type=image,name=gcr.io/${{ env.PROJECT_ID }}/${{ env.IMAGE_NAME }},push-by-digest=true,name-canonical=true,push=${{ github.event_name != 'pull_request' && env.SERVICE_ACCOUNT != '' }}
cache-from: type=gha,scope=${{ matrix.runner }}
cache-to: type=gha,scope=${{ matrix.runner }},mode=max
- name: Export digest
if: ${{ github.event_name != 'pull_request' && env.SERVICE_ACCOUNT != '' }}
run: |
mkdir -p /tmp/digests
digest="${DIGEST}"
touch "/tmp/digests/${digest#sha256:}"
env:
DIGEST: ${{ steps.build.outputs.digest }}
- name: Upload digest
if: ${{ github.event_name != 'pull_request' && env.SERVICE_ACCOUNT != '' }}
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: digests-${{ matrix.runner }}
path: /tmp/digests/*
if-no-files-found: error
retention-days: 1
docker-merge:
name: Docker Merge
runs-on: ubuntu-24.04
if: ${{ github.event_name != 'pull_request' && github.repository == 'hexpm/hexdocs' }}
needs: docker
permissions:
contents: "read"
id-token: "write"
env:
IMAGE_NAME: "hexdocs"
PROJECT_ID: "hexpm-prod"
SERVICE_ACCOUNT: ${{ secrets.GCLOUD_SERVICE_ACCOUNT }}
WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCLOUD_WORKFLOW_IDENTITY_POOL_PROVIDER }}
steps:
- name: Set short git commit SHA
run: echo "COMMIT_SHORT_SHA=${GITHUB_SHA::7}" >> $GITHUB_ENV
- name: Download digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: /tmp/digests
pattern: digests-*
merge-multiple: true
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
- name: Google auth
id: auth
uses: "google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093" # v3.0.0
with:
token_format: "access_token"
project_id: ${{ env.PROJECT_ID }}
service_account: ${{ env.SERVICE_ACCOUNT }}
workload_identity_provider: ${{ env.WORKLOAD_IDENTITY_PROVIDER }}
- name: Docker Auth
uses: "docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2" # v4.0.0
with:
registry: gcr.io
username: "oauth2accesstoken"
password: "${{ steps.auth.outputs.access_token }}"
- name: Create manifest list and push
working-directory: /tmp/digests
run: |
docker buildx imagetools create \
-t gcr.io/${PROJECT_ID}/${IMAGE_NAME}:${COMMIT_SHORT_SHA} \
$(printf "gcr.io/${PROJECT_ID}/${IMAGE_NAME}@sha256:%s " *)