Merge remote-tracking branch 'origin/master' into feat/update_sonar_docs
# Conflicts: # documentation/chapters/templates/tool-sonar7.adoc
This commit is contained in:
commit
1b1e789860
@ -23,11 +23,11 @@ check_confluence_validity:
|
||||
INPUT_FILE: "document.adoc"
|
||||
IMAGES_DIR: images
|
||||
CREATE_SUB_PAGES: "false"
|
||||
PAGE_PREFIX: "[CI/CD] - [TMPL] - "
|
||||
PAGE_PREFIX: "[CI/CD] - "
|
||||
CONFLUENCE_SPACE: RANDI
|
||||
TEXT_GENERATED_HINT: '<ac:structured-macro ac:name="warning"><ac:parameter ac:name="title" /><ac:rich-text-body>This is a generated page, do not edit! All changes must happen in the <a href="${CI_PROJECT_URL}">Repository</a>
|
||||
.</ac:rich-text-body></ac:structured-macro>'
|
||||
FILE_INPUT: "index.html,111183157,gitlab-ci-templates"
|
||||
FILE_INPUT: "index.html,107524048,CI Templates"
|
||||
extends: .check_confluence_validity-template
|
||||
|
||||
pages:
|
||||
@ -36,11 +36,11 @@ pages:
|
||||
INPUT_FILE: "document.adoc"
|
||||
IMAGES_DIR: images
|
||||
CREATE_SUB_PAGES: "false"
|
||||
PAGE_PREFIX: "[CI/CD] - [TMPL] - "
|
||||
PAGE_PREFIX: "[CI/CD] - "
|
||||
CONFLUENCE_SPACE: RANDI
|
||||
TEXT_GENERATED_HINT: '<ac:structured-macro ac:name="warning"><ac:parameter ac:name="title" /><ac:rich-text-body>This is a generated page, do not edit! All changes must happen in the <a href="${CI_PROJECT_URL}">Repository</a>
|
||||
.</ac:rich-text-body></ac:structured-macro>'
|
||||
FILE_INPUT: "index.html,111183157,gitlab-ci-templates"
|
||||
FILE_INPUT: "index.html,107524048,CI Templates"
|
||||
extends: .pages-template
|
||||
|
||||
.release-template:
|
||||
|
||||
@ -46,7 +46,7 @@
|
||||
EXTRA_ARGS: $GRADLE_EXTRA_ARGS
|
||||
script:
|
||||
- echo $PARSED_VERSION
|
||||
- ./gradlew assemble jib $EXTRA_ARGS
|
||||
- ./gradlew assemble jib $GRADLE_CLI_OPTS $EXTRA_ARGS
|
||||
"-DskipTests"
|
||||
"-Djib.to.image=$DOCKER_REGISTRY:$PARSED_VERSION""
|
||||
"-Djib.to.auth.username=$DOCKER_REGISTRY_USER"
|
||||
|
||||
@ -2,7 +2,7 @@
|
||||
image: $MAVEN_IMAGE
|
||||
stage: test
|
||||
variables:
|
||||
TRIVY_VERSION: 0.24.1
|
||||
TRIVY_VERSION: 0.24.2
|
||||
EXITCODE: 1
|
||||
TRIVY_EXTRA_ARGS: "--no-progress --ignore-unfixed"
|
||||
before_script:
|
||||
@ -23,7 +23,7 @@
|
||||
image: $GRADLE_IMAGE
|
||||
stage: test
|
||||
variables:
|
||||
TRIVY_VERSION: 0.24.1
|
||||
TRIVY_VERSION: 0.24.2
|
||||
EXITCODE: 1
|
||||
PROJECT_DIR: $CI_PROJECT_DIR/build
|
||||
TRIVY_EXTRA_ARGS: "--no-progress --ignore-unfixed"
|
||||
@ -32,7 +32,7 @@
|
||||
- curl -L "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz" --output trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz
|
||||
- tar zxvf trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz
|
||||
script:
|
||||
- ./gradlew jibBuildTar -DskipTests
|
||||
- ./gradlew $GRADLE_CLI_OPTS jibBuildTar -DskipTests
|
||||
- ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code 0 --severity HIGH,CRITICAL --format template --template "@contrib/junit.tpl" -o junit-report.xml --input $PROJECT_DIR/jib-image.tar
|
||||
- ./trivy --cache-dir .trivycache/ image --timeout 15m $TRIVY_EXTRA_ARGS --exit-code $EXITCODE --severity HIGH,CRITICAL --input $PROJECT_DIR/jib-image.tar
|
||||
cache:
|
||||
@ -48,7 +48,7 @@
|
||||
name: gcr.io/kaniko-project/executor:debug
|
||||
entrypoint: [ "" ]
|
||||
variables:
|
||||
TRIVY_VERSION: 0.24.1
|
||||
TRIVY_VERSION: 0.24.2
|
||||
PROJECT_DIR: $CI_PROJECT_DIR
|
||||
DOCKERFILE_LOCATION: $CI_PROJECT_DIR/Dockerfile
|
||||
CONTEXT_LOCATION: $CI_PROJECT_DIR
|
||||
|
||||
@ -19,6 +19,7 @@ Falls das Projekt aus mehreren Poms besteht, kann `before_script:` benutzt werde
|
||||
|EXTRA_ARGS | Weitere Argumente die an den jeweiligen Job gegeben werden sollen. | ""
|
||||
|USE_VERSIONFILE | Wenn true, dann wird zur Versionierung das ./version file aus dem set-version tool verwendet | "false"
|
||||
|ARTIFACT | Der Name des Versionfiles aus dem set-version tool | "version"
|
||||
|GRADLE_CLI_OPTS | Zusätzliche CLI Opts für Gradle | ""
|
||||
|===
|
||||
|
||||
.container-publish
|
||||
|
||||
@ -22,6 +22,7 @@ Benutzte `allow_failure: true` damit die CI weiter läuft aber ein Failure angez
|
||||
Wenn 0 benutzt wird, läuft die CI weiter.
|
||||
Benutzte `allow_failure: true` damit die CI weiter läuft aber ein Failure angezeigt wird.
|
||||
| -
|
||||
|GRADLE_CLI_OPTS | Zusätzliche CLI Opts für Gradle | ""
|
||||
|===
|
||||
|
||||
.container scan template
|
||||
|
||||
@ -8,6 +8,7 @@ Die Ergebnisse werden als Artifact gespeichert.
|
||||
.Variables
|
||||
|===
|
||||
|Name |Description | Default Value
|
||||
|GRADLE_CLI_OPTS | Zusätzliche CLI Opts für Gradle | ""
|
||||
|===
|
||||
|
||||
.gradle-build-template
|
||||
|
||||
@ -8,6 +8,7 @@ Die Ergebnisse werden als Artifact gespeichert.
|
||||
.Variables
|
||||
|===
|
||||
|Name |Description | Default Value
|
||||
|GRADLE_CLI_OPTS | Zusätzliche CLI Opts für Gradle | ""
|
||||
|===
|
||||
|
||||
.gradle-test-template
|
||||
|
||||
@ -13,11 +13,14 @@ Mehr Details zu finden hier: https://gitlab.exxcellent.de/gilden/ci/exxcellent-s
|
||||
|SONAR_PROJECT_KEY | Der Sonar-Projekt-Key. | ""
|
||||
|SONAR_PROJECT_NAME | Der Sonar-Projekt-Name. | "" (Es wird dann standardmäßig der Maven project.name verwendet)
|
||||
|SONAR_EXCLUSIONS | Von Sonar auszuschließende Bereiche | **/target/**,**/src/test/**
|
||||
|
||||
|GRADLE_CLI_OPTS | Zusätzliche CLI Opts für Gradle | ""
|
||||
|
||||
|===
|
||||
|
||||
TIP: Der SONAR_TOKEN String kann über den persönlichen User Bereich in Sonar unter dem Tab _Security_ erzeugt werden. Ein technischer User ist aktuell nicht möglich. Das Token wird ausschließlich dafür benötigt, wenn der Sonar Buildbreaker über die Pipeline aktiviert wird (_sonar.buildbreaker.skip=true_). Wenn der Build nicht gebrochen werden soll, kann es weggelassen werden.
|
||||
TIP: Der SONAR_TOKEN String kann über den persönlichen User Bereich in Sonar unter dem Tab _Security_ erzeugt werden.
|
||||
Ein technischer User ist aktuell nicht möglich.
|
||||
Das Token wird ausschließlich dafür benötigt, wenn der Sonar Buildbreaker über die Pipeline aktiviert wird (_sonar.buildbreaker.skip=true_).
|
||||
Wenn der Build nicht gebrochen werden soll, kann es weggelassen werden.
|
||||
|
||||
.sonar-template
|
||||
[source,yaml]
|
||||
|
||||
@ -2,7 +2,7 @@
|
||||
image: $GRADLE_IMAGE
|
||||
stage: test
|
||||
script:
|
||||
- "./gradlew --build-cache test"
|
||||
- "./gradlew --build-cache test $GRADLE_CLI_OPTS"
|
||||
artifacts:
|
||||
expire_in: 2 weeks
|
||||
reports:
|
||||
|
||||
@ -27,7 +27,7 @@
|
||||
extends: .sonar-template-common
|
||||
image: $GRADLE_IMAGE
|
||||
script:
|
||||
- ./gradlew $GRADLE_OPTS sonarqube
|
||||
- ./gradlew $GRADLE_OPTS sonarqube $GRADLE_CLI_OPTS
|
||||
"-Dsonar.host.url=$SONAR_HOST_URL"
|
||||
"-Dsonar.login=$SONAR_TOKEN"
|
||||
"-Dsonar.projectKey=$SONAR_PROJECT_KEY"
|
||||
|
||||
Loading…
Reference in New Issue
Block a user