Skip to content

chore: harden GitHub Actions for platform compliance #1461

chore: harden GitHub Actions for platform compliance

chore: harden GitHub Actions for platform compliance #1461

Workflow file for this run

name: Test and Deploy
on:
push:
branches: [ '*' ]
tags: [ '*' ]
pull_request:
branches: [ main ]
schedule:
# Run automatically at 8AM PST Monday-Friday
- cron: '0 15 * * 1-5'
workflow_dispatch:
jobs:
test:
name: Test
runs-on: ubuntu-x64
if: github.repository_owner == 'sendgrid'
timeout-minutes: 20
permissions:
contents: read
strategy:
matrix:
java: [ 8, 11 ]
env:
DOCKER_LOGIN: ${{ secrets.DOCKER_USERNAME && secrets.DOCKER_AUTH_TOKEN }}
steps:
- name: Checkout sendgrid-java
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
# Plain CLI login: docker/login-action is not on this org's action allowlist.
- name: Login to Docker Hub
if: env.DOCKER_LOGIN
env:
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
DOCKER_AUTH_TOKEN: ${{ secrets.DOCKER_AUTH_TOKEN }}
run: echo "$DOCKER_AUTH_TOKEN" | docker login -u "$DOCKER_USERNAME" --password-stdin
- name: Install Docker Compose
run: |
sudo apt-get update
sudo apt-get install -y docker-compose
- name: Run Unit Tests
run: make test-docker version=${{ matrix.java }}
deploy:
name: Deploy
if: success() && github.ref_type == 'tag' && github.repository_owner == 'sendgrid'
needs: [ test ]
runs-on: ubuntu-x64
permissions:
contents: write
steps:
- name: Checkout sendgrid-java
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
# The release action verifies refs/tags/<tag> in the local clone.
fetch-depth: 0
- name: Set up Sonatype Maven
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1
with:
java-version: '8'
distribution: temurin
server-id: central
server-username: MAVEN_USERNAME
server-password: MAVEN_PASSWORD
gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }}
gpg-passphrase: GPG_PASSPHRASE
- name: Install dependencies and Build Release Artifacts
run: make install
- name: Create GitHub Release
uses: twilio/sdk-actions/github-release@9b1c3222c9ffe38aadedb11c5b9f5a172b5e9951 # v1
with:
assets: sendgrid-java.jar
changelog-file: CHANGELOG.md
footer: '**[Maven](https://mvnrepository.com/artifact/com.sendgrid/sendgrid-java/${{ github.ref_name }})**'
- name: Publish to Maven
env:
MAVEN_USERNAME: ${{ secrets.SONATYPE_USERNAME }}
MAVEN_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: mvn clean deploy -DskipTests=true -B -U -Prelease
# - name: Submit metric to Datadog
# uses: sendgrid/dx-automator/actions/datadog-release-metric@08b601b726671445abc798ed59881766ec8fefc6 # main
# env:
# DD_API_KEY: ${{ secrets.DATADOG_API_KEY }}
# notify-on-failure:
# name: Slack notify on failure
# if: failure() && github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || github.ref_type == 'tag')
# needs: [ test, deploy ]
# runs-on: ubuntu-x64
# steps:
# - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2.3.3
# env:
# SLACK_COLOR: failure
# SLACK_ICON_EMOJI: ':github:'
# SLACK_MESSAGE: ${{ format('Test *{0}*, Deploy *{1}*, {2}/{3}/actions/runs/{4}', needs.test.result, needs.deploy.result, github.server_url, github.repository, github.run_id) }}
# SLACK_TITLE: Action Failure - ${{ github.repository }}
# SLACK_USERNAME: GitHub Actions
# SLACK_MSG_AUTHOR: twilio-dx
# SLACK_FOOTER: Posted automatically using GitHub Actions
# SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }}
# MSG_MINIMAL: true