Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 49 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
name: CI

on:
pull_request:
branches: [master]

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
test:
name: tests and coverage
runs-on: cx-public-ubuntu-x64
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
with:
node-version: 22
# Runner cannot reach registry.npmjs.org; install through the echohq registry, as in test_action.yaml
- name: Install dependencies through echohq registry
env:
ECHO_LIBRARIES_ACCESS_KEY: ${{ secrets.ECHO_LIBRARIES_ACCESS_KEY }}
run: |
NPMRC="${RUNNER_TEMP}/npmrc"
umask 077
printf 'registry=https://npm.echohq.com/\n//npm.echohq.com/:_authToken=%s\n' "${ECHO_LIBRARIES_ACCESS_KEY}" > "${NPMRC}"
npm ci --ignore-scripts --userconfig "${NPMRC}"
rm -f "${NPMRC}"
- name: Run tests with coverage
run: npm run test:coverage

shellcheck:
name: shellcheck entrypoint
runs-on: cx-public-ubuntu-x64
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
# entrypoint.sh runs under busybox ash in the action image
- name: Lint entrypoint.sh
run: docker run --rm -v "${PWD}:/mnt:ro" koalaman/shellcheck@sha256:2097951f02e735b613f4a34de20c40f937a6c8f18ecb170612c88c34517221fb --shell=busybox --severity=error entrypoint.sh # v0.10.0
72 changes: 72 additions & 0 deletions .github/workflows/coverage-badge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
name: coverage-badge

on:
push:
branches: [master]

concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false

permissions:
contents: read

jobs:
coverage:
name: generate-coverage
runs-on: cx-public-ubuntu-x64
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6.3.0
with:
node-version: 22
# Runner cannot reach registry.npmjs.org; install through the echohq registry, as in test_action.yaml
- name: Install dependencies through echohq registry
env:
ECHO_LIBRARIES_ACCESS_KEY: ${{ secrets.ECHO_LIBRARIES_ACCESS_KEY }}
run: |
NPMRC="${RUNNER_TEMP}/npmrc"
umask 077
printf 'registry=https://npm.echohq.com/\n//npm.echohq.com/:_authToken=%s\n' "${ECHO_LIBRARIES_ACCESS_KEY}" > "${NPMRC}"
npm ci --ignore-scripts --userconfig "${NPMRC}"
rm -f "${NPMRC}"
- name: Run tests with coverage
run: npm run test:coverage
- name: Generate badge
run: node scripts/coverage-badge.js coverage/lcov.info coverage/badge.json
- name: Upload coverage badge Artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: coverage-badge
path: coverage/badge.json

publish:
name: publish-coverage
needs: coverage
runs-on: cx-public-ubuntu-x64
timeout-minutes: 5
permissions:
contents: write # for git push to the badges branch
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
ref: badges
persist-credentials: true
- name: Download Badge json
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: coverage-badge
path: latest-coverage
- name: Push badge to the badges branch
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
mv latest-coverage/badge.json coverage.json
git add coverage.json
if ! git status | grep "nothing to commit"; then
git commit -m 'chore(tests): updating test coverage badge'
git push origin badges
fi
3 changes: 2 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
@@ -1,2 +1,3 @@
node_modules
.vscode
.vscode
coverage
21 changes: 21 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
[![License: GPL-3.0](https://img.shields.io/badge/License-GPL3.0-yellow.svg)](https://www.gnu.org/licenses)
[![Latest Release](https://img.shields.io/github/v/release/checkmarx/kics-github-action)](https://github.com/checkmarx/kics-github-action/releases)
[![Open Issues](https://img.shields.io/github/issues-raw/checkmarx/kics-github-action)](https://github.com/checkmarx/kics-github-action/issues)
[![Coverage](https://img.shields.io/endpoint?url=https%3A%2F%2Fraw.githubusercontent.com%2FCheckmarx%2Fkics-github-action%2Fbadges%2Fcoverage.json)](https://github.com/Checkmarx/kics-github-action/actions/workflows/coverage-badge.yml)

- [KICS GitHub Action](#kics-github-action)
- [Integrate KICS into your GitHub workflows](#integrate-kics-into-your-github-workflows)
Expand All @@ -20,6 +21,7 @@
- [Uploading SARIF report](#uploading-sarif-report)
- [Using configuration file](#using-configuration-file)
- [How To Contribute](#how-to-contribute)
- [Running the tests](#running-the-tests)
- [License](#license)

## Integrate KICS into your GitHub workflows
Expand Down Expand Up @@ -448,6 +450,25 @@ jobs:

We welcome [issues](https://github.com/checkmarx/kics-github-action/issues) to and [pull requests](https://github.com/checkmarx/kics-github-action/pulls) against this repository!

### Running the tests

Requires Node.js 22 or newer.

```sh
npm ci
npm test # unit and end-to-end tests
npm run test:coverage # same, plus a coverage report and the coverage gate used by CI
```

Tests live under `test/`:

- `test/unit` - the PR comment and job summary logic against a fake GitHub API
- `test/e2e` - the action run as a workflow would run it: `src/main.js` as a process, `entrypoint.sh` against a fake `kics`, and the `action.yml` contract
- `test/helpers` and `test/fixtures` - the fake GitHub API, KICS report builders and process runners

Tests marked with `knownBug` document known bugs: they are reported as `todo` and are expected to fail until the bug is fixed.
They are skipped in the coverage run, so coverage only counts verified behaviour.

# License

KICS Github Action
Expand Down
139 changes: 1 addition & 138 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading