Repository navigation
110 lines (107 loc) · 3.91 KB
/
Copy pathquality.yml
File metadata and controls
110 lines (107 loc) · 3.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
name: quality
on:
workflow_call:
inputs:
image-tag:
description: code-quality image tag
type: string
default: v1
checks:
description: Space-separated check IDs; empty means all detected checks
type: string
default: ""
setup:
description: Shell command run before checking (for example `composer install`)
type: string
default: ""
working-directory:
description: Consumer working directory inside /work
type: string
default: "."
report:
description: Run code-quality report after check and upload artifacts/quality
type: boolean
default: false
coverage-artifact:
description: Artifact holding coverage/coverage-final.json for the fallow-health report
type: string
default: ""
permissions:
contents: read
packages: read
jobs:
quality:
runs-on: ubuntu-latest
container:
image: ghcr.io/runroom/code-quality:${{ inputs.image-tag }}
credentials:
username: ${{ github.actor }}
password: ${{ github.token }}
options: --user root
steps:
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
fetch-depth: 0
- name: Setup
if: inputs.setup != ''
working-directory: ${{ inputs.working-directory }}
env:
CODE_QUALITY_SETUP: ${{ inputs.setup }}
run: bash -e -c "$CODE_QUALITY_SETUP"
- name: Validate checks
env:
CODE_QUALITY_CHECKS: ${{ inputs.checks }}
shell: bash
run: |
if ! printf '%s' "$CODE_QUALITY_CHECKS" | grep -Eq '^[a-z ]*$'; then
echo "Invalid checks input: only lowercase check ids separated by spaces are allowed" >&2
exit 1
fi
- name: Validate coverage artifact
id: validate-coverage
if: ${{ inputs.report && inputs.coverage-artifact != '' }}
env:
CODE_QUALITY_COVERAGE_ARTIFACT: ${{ inputs.coverage-artifact }}
shell: bash
run: |
if ! printf '%s' "$CODE_QUALITY_COVERAGE_ARTIFACT" | grep -Eq '^[A-Za-z0-9._-]+$'; then
echo "Invalid coverage artifact input" >&2
exit 1
fi
- name: Check
id: check
working-directory: ${{ inputs.working-directory }}
env:
CODE_QUALITY_CHECKS: ${{ inputs.checks }}
shell: bash
run: |
read -ra CHECKS <<< "$CODE_QUALITY_CHECKS"
code-quality check "${CHECKS[@]}"
- name: Download coverage
id: download-coverage
if: ${{ inputs.report && inputs.coverage-artifact != '' && !cancelled() && steps.validate-coverage.outcome == 'success' }}
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ inputs.coverage-artifact }}
path: ${{ inputs.working-directory }}/coverage
- name: Report
id: report
if: ${{ inputs.report && !cancelled() && steps.check.outcome != 'skipped' && steps.validate-coverage.outcome != 'failure' && (inputs.coverage-artifact == '' || steps.download-coverage.outcome == 'success') }}
working-directory: ${{ inputs.working-directory }}
env:
CODE_QUALITY_COVERAGE_ARTIFACT: ${{ inputs.coverage-artifact }}
shell: bash
run: |
if [[ -n "$CODE_QUALITY_COVERAGE_ARTIFACT" ]]; then
code-quality report --coverage coverage/coverage-final.json
else
code-quality report
fi
- name: Upload quality reports
if: ${{ inputs.report && !cancelled() && steps.report.outcome != 'skipped' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: quality-reports
path: ${{ inputs.working-directory }}/artifacts/quality
if-no-files-found: warn
retention-days: 14