diff --git a/.github/workflows/deploy-ALPHA.yml b/.github/workflows/deploy-ALPHA.yml index 75cf0bd3e..e9481e554 100644 --- a/.github/workflows/deploy-ALPHA.yml +++ b/.github/workflows/deploy-ALPHA.yml @@ -7,43 +7,43 @@ ####################################### # Start the job on all push to master # ####################################### -name: 'Build & Deploy - ALPHA' +name: "Build & Deploy - ALPHA" on: push: branches: - - 'alpha' + - "alpha" ############### # Set the Job # ############### jobs: - deploy: - name: Deploy alpha - runs-on: ubuntu-latest - permissions: read-all - environment: - name: alpha - steps: - - uses: actions/checkout@v4 - # Setup .npmrc file to publish to npm - - uses: actions/setup-node@v4 - with: - node-version: 20 - registry-url: 'https://registry.npmjs.org' - always-auth: true - # Defaults to the user or organization that owns the workflow file - scope: 'hardisgroupcom' - - run: yarn install --frozen-lockfile && yarn run compile - - run: yarn config set version-git-tag false - - run: ALPHAID=$(date '+%Y%m%d%H%M') && yarn version --prepatch --preid="alpha$ALPHAID" - - run: yarn config set network-timeout 300000 - - run: yarn publish --tag alpha - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + # deploy: + # name: Deploy alpha + # runs-on: ubuntu-latest + # permissions: read-all + # environment: + # name: alpha + # steps: + # - uses: actions/checkout@v4 + # # Setup .npmrc file to publish to npm + # - uses: actions/setup-node@v4 + # with: + # node-version: 20 + # registry-url: 'https://registry.npmjs.org' + # always-auth: true + # # Defaults to the user or organization that owns the workflow file + # scope: 'hardisgroupcom' + # - run: yarn install --frozen-lockfile && yarn run compile + # - run: yarn config set version-git-tag false + # - run: ALPHAID=$(date '+%Y%m%d%H%M') && yarn version --prepatch --preid="alpha$ALPHAID" + # - run: yarn config set network-timeout 300000 + # - run: yarn publish --tag alpha + # env: + # NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} push_alpha_to_registry: name: Push alpha Docker image to Docker Hub - needs: deploy + # needs: deploy runs-on: ubuntu-latest permissions: packages: write @@ -92,17 +92,17 @@ jobs: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: - image-ref: 'docker.io/hardisgroupcom/sfdx-hardis:alpha' - format: 'table' - exit-code: '1' + image-ref: "docker.io/hardisgroupcom/sfdx-hardis:alpha" + format: "table" + exit-code: "1" ignore-unfixed: true - vuln-type: 'os,library' + vuln-type: "os,library" security-checks: vuln - severity: 'CRITICAL,HIGH' + severity: "CRITICAL,HIGH" push_alpha_to_registry_sfdx_recommended: name: Push alpha Docker image to Docker Hub (with @salesforce/cli version recommended by hardis) - needs: deploy + # needs: deploy runs-on: ubuntu-latest permissions: packages: write @@ -151,10 +151,10 @@ jobs: - name: Run Trivy vulnerability scanner uses: aquasecurity/trivy-action@master with: - image-ref: 'docker.io/hardisgroupcom/sfdx-hardis:alpha-sfdx-recommended' - format: 'table' - exit-code: '1' + image-ref: "docker.io/hardisgroupcom/sfdx-hardis:alpha-sfdx-recommended" + format: "table" + exit-code: "1" ignore-unfixed: true - vuln-type: 'os,library' + vuln-type: "os,library" security-checks: vuln - severity: 'CRITICAL,HIGH' + severity: "CRITICAL,HIGH"