name: CI on: pull_request: push: branches: - main tags: - "v*.*.*" permissions: contents: read packages: write id-token: write env: IMAGE_NAME: ghcr.io/${{ github.repository }} PYTHON_VERSION: "3.14" POETRY_VERSION: "2.4.1" jobs: verify: name: Test and lint runs-on: ubuntu-latest steps: - name: Check out repository uses: actions/checkout@v4 with: fetch-depth: 0 - name: Set up Python uses: actions/setup-python@v5 with: python-version: ${{ env.PYTHON_VERSION }} - name: Install Poetry run: pipx install poetry==${{ env.POETRY_VERSION }} - name: Configure Poetry cache uses: actions/cache@v4 with: path: ~/.cache/pypoetry key: poetry-${{ runner.os }}-${{ env.PYTHON_VERSION }}-${{ hashFiles('poetry.lock') }} restore-keys: | poetry-${{ runner.os }}-${{ env.PYTHON_VERSION }}- - name: Install dependencies run: poetry install --with dev --no-interaction --no-ansi --no-root - name: Run secret scanning uses: gitleaks/gitleaks-action@v2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Run lint run: poetry run ruff check src tests scripts - name: Run tests run: poetry run pytest -q docker: name: Build, sign, and publish image runs-on: ubuntu-latest needs: verify steps: - name: Check out repository uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Log in to GHCR if: github.event_name == 'push' uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract Docker metadata id: meta uses: docker/metadata-action@v5 with: images: ${{ env.IMAGE_NAME }} tags: | type=ref,event=branch type=ref,event=tag type=sha,prefix=sha- - name: Build and push image id: build uses: docker/build-push-action@v6 with: context: . target: runtime push: ${{ github.event_name == 'push' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max - name: Generate SBOM if: github.event_name == 'push' uses: aquasecurity/trivy-action@master with: image-ref: ${{ env.IMAGE_NAME }}:${{ steps.meta.outputs.version }} format: cyclonedx output: sbom.cyclonedx.json - name: Upload SBOM if: github.event_name == 'push' uses: actions/upload-artifact@v4 with: name: sbom path: sbom.cyclonedx.json - name: Install cosign if: github.event_name == 'push' uses: sigstore/cosign-installer@v3 - name: Sign container image if: github.event_name == 'push' env: DIGEST: ${{ steps.build.outputs.digest }} run: | cosign sign --yes \ "${{ env.IMAGE_NAME }}@${DIGEST}"