Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
T
Textgrid Repository WebDAV Server
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package registry
Container Registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Service Desk
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
DARIAH-DE
TextGridRep
Textgrid Repository WebDAV Server
Commits
55820333
Verified
Commit
55820333
authored
2 years ago
by
Stefan Hynek
Browse files
Options
Downloads
Patches
Plain Diff
ci(gitlab): add job that generates pipfiles for better dependency detection
parent
25f31acb
No related branches found
No related tags found
1 merge request
!26
Resolve "repair sbom generation and upload"
Pipeline
#343199
passed
2 years ago
Stage: build
Changes
1
Pipelines
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
.gitlab-ci.yml
+19
-6
19 additions, 6 deletions
.gitlab-ci.yml
with
19 additions
and
6 deletions
.gitlab-ci.yml
+
19
−
6
View file @
55820333
...
...
@@ -56,10 +56,9 @@ build container image:
name
:
gcr.io/kaniko-project/executor:debug
entrypoint
:
[
"
"
]
script
:
# always succeed and don't print error message
-
tag=$(git tag --contains $CI_COMMIT_SHORT_SHA 2>&1) ||
true
# use tag for version if not empty; else commit sha
-
"
[[
-n
$tag
]]
&&
export
version=$tag
||
export
version=$CI_COMMIT_SHORT_SHA"
-
"
[[
-n
${CI_COMMIT_TAG}
]]
&&
export
version=${CI_COMMIT_TAG}
||
export
version=${CI_COMMIT_SHORT_SHA}"
-
echo $version
-
mkdir -p /kaniko/.docker
-
echo "{\"auths\":{\"$CI_REGISTRY\":{\"auth\":\"$(echo -n ${CI_REGISTRY_USER}:${CI_REGISTRY_PASSWORD} | base64 | tr -d '\n')\"},\"$harbor_registry\":{\"auth\":\"$HARBOR_ROBOT_TOKEN64\"}}}" > /kaniko/.docker/config.json
-
/kaniko/executor
...
...
@@ -78,20 +77,33 @@ build container image:
-
if
:
$CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
-
if
:
$CI_COMMIT_TAG
generate pipfile
:
stage
:
build
image
:
docker.io/python:3.8-alpine
before_script
:
-
pip install pipenv
script
:
-
pipenv lock
artifacts
:
paths
:
-
Pipfile*
needs
:
[]
rules
:
-
if
:
$CI_COMMIT_TAG
generate app sbom
:
stage
:
deploy
image
:
docker.io/node:18.12
before_script
:
-
npm ci --ignore-scripts
-
npm run build
script
:
-
npx cdxgen
--type nodejs
--required-only
--type python
--server-url https://deps.sub.uni-goettingen.de
--api-key ${DEPS_UPLOAD_TOKEN}
--project-name ${project_name}
--project-version ${CI_COMMIT_TAG}
needs
:
[
"
generate
pipfile"
]
rules
:
-
if
:
$CI_COMMIT_TAG
...
...
@@ -112,5 +124,6 @@ generate container sbom:
--form
"projectName=${project_name}-container"
--form
"projectVersion=${CI_COMMIT_TAG}"
--form
"bom=@bom.json"'
needs
:
[
"
build
container
image"
]
rules
:
-
if
:
$CI_COMMIT_TAG
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment