Skip to content

Kubectl release version fix cve #111

Kubectl release version fix cve

Kubectl release version fix cve #111

Workflow file for this run

name: Branch Build halyard
on:
workflow_call:
push:
branches:
- bugfix/OP-22783-vOES-1.33.x
env:
GRADLE_OPTS: -Dorg.gradle.daemon=false -Xmx6g -Xms6g
CONTAINER_REGISTRY: quay.io/opsmxpublic
jobs:
branch-build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
with:
fetch-depth: 0
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- uses: actions/setup-java@v2
with:
java-version: 17
distribution: 'temurin'
- name: Prepare build variables
id: build_variables
run: |
echo ::set-output name=REPO::ubi8-halyard-cve
#echo ::set-output name=VERSION::"1.65.0$(date --utc +'%Y%m%d%H%M')"
#echo ::set-output name=VERSION::"1.65.0$(date --utc +'%Y%m%d')"
#echo ::set-output name=VERSION::"1.65.0$(date --utc +'%-m%d')"
echo ::set-output name=VERSION::"oc-1.65.0"
echo "::set-output name=GITHASH::$(git rev-parse --short HEAD)"
echo "::set-output name=BUILDDATE::$(date -u +"%Y%m%d%H%M")"
- name: Login to Quay
uses: docker/login-action@v1
# use service account flow defined at: https://github.com/docker/login-action#service-account-based-authentication-1
with:
registry: quay.io
username: ${{ secrets.QUAY_USERNAME }}
password: ${{ secrets.QUAY_KEY }}
- name: Build
env:
ORG_GRADLE_PROJECT_version: ${{ steps.build_variables.outputs.VERSION }}
run: |
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i settings.gradle
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i settings.gradle
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i build.gradle
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i build.gradle
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i settings.gradle
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i build.gradle
./gradlew --no-daemon -PenableCrossCompilerPlugin=true halyard-web:installDist -x test
- name: dockerBuildpushFips
uses: docker/build-push-action@v2
with:
context: .
file: docker/ubi8/Dockerfile-fips
push: true
tags: |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}"
- name: dockerBuildpushDev
uses: docker/build-push-action@v2
with:
context: .
file: docker/ubi8/Dockerfile-dev
push: true
tags: |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}-dev"
- id: get-build-name
run: |
imageName="${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}"
echo "clouddriver=$imageName" >> $GITHUB_OUTPUT
echo "clouddriverDev=$imageName"-dev >> $GITHUB_OUTPUT