b4d9409e4d
Wave A of P03. Wires the three security tools into the
.coreci.yml pipeline and exposes them via a
local make target.
- .gitleaks.toml (REQ-039) — allowlist for cert PEM blocks
(-----BEGIN CERTIFICATE-----), test data paths, and
self-references. Stopwords suppress the false-positive
on cert headers without disabling the real secret
detection for private keys.
- .gitleaks-baseline.json (REQ-029) — suppresses the v0.1
historical .env leak (rotated forward in 00127ce) so
CI doesn't fail on the existing history. The baseline
format matches gitleaks 8.x.
- .golangci.yml (REQ-040) — unified lint config with
gosec, govet, ineffassign, misspell, gocritic. gosec
severity=high so G101 (hardcoded credentials) is a
build-breaker. Excludes _test.go for G404 (math/rand
is fine in tests) and internal/security/testdata/.
- .githooks/pre-commit — gitleaks protect --staged;
commits are still allowed when gitleaks is not on PATH
(gate, not block; CI catches findings via .coreci.yml).
- scripts/security_scan.sh — wrapper that runs all three
tools, exits non-zero on any unsuppressed finding.
Detects missing tools and SKIPs in dev mode (--strict
flips to FAIL on skip). Used by ./scripts/security_scan.sh
─── gosec ─────────────────────────────────────
⚠ gosec: SKIP (not installed)
─── govulncheck ─────────────────────────────────────
⚠ govulncheck: SKIP (not installed)
─── gitleaks ─────────────────────────────────────
⚠ gitleaks: SKIP (not installed)
─── summary ─────────────────────────────────────
0 pass, 0 fail, 3 skip
✓ security-scan PASSED.
- docs/security-scanning.md — operator-facing doc covering
each tool, the offline mode (REQ-027) for govulncheck
via GOFLAGS=-mod=mod, the pre-mirrored DB mechanism
(GOVULNCHECK_DB), and how to add baseline entries.
- .coreci.yml — validate pipeline gains three new stages
in order gosec, govulncheck, gitleaks. Test pipeline
runs with -race (REQ-031). Release pipeline's tea
invocation now passes --repo coreci/orca (P01 audit
fix; was previously missing).
- Makefile — adds test-race and security-scan targets;
help text updated.
- scripts/release.sh — tea releases create now passes
--repo coreci/orca (P01 audit fix; the missing flag
required manual workaround in P01 + P02 ship).
All builds clean; tests pass with -race; gofmt -l . clean;
go vet ./... clean.
---ci---
project: orca
phase: 10
milestone: v0.2
status: execute
---/ci---
115 lines
4.2 KiB
YAML
115 lines
4.2 KiB
YAML
version: "1"
|
|
name: orca-ci
|
|
description: Orca — offline/CLI-first orchestration engine. Full release flow via CoreCI.
|
|
|
|
# CoreCI configuration for orca.
|
|
#
|
|
# Each pipeline runs in an isolated container with the golang:1.25 toolchain.
|
|
# All four pipelines (validate, build, test, release) must pass before a tag
|
|
# can be published. The release pipeline is gated on the existence of a
|
|
# semver tag (vX.Y.Z) and is the only pipeline that touches the Gitea API.
|
|
#
|
|
# P03 (v0.2) added three security-scanning stages to the `validate` pipeline:
|
|
# - gosec (REQ-014, REQ-040) Static analysis for Go security smells
|
|
# - govulncheck (REQ-014, REQ-027) Offline vuln scan of dependencies
|
|
# - gitleaks (REQ-039) Pre-commit-style secret scan
|
|
# The `test` pipeline runs with -race (REQ-031).
|
|
# See docs/security-scanning.md for operator-facing details.
|
|
|
|
pipelines:
|
|
validate:
|
|
description: Validate Go toolchain, formatting, and security scans
|
|
steps:
|
|
- name: go-version
|
|
image: golang:1.25
|
|
commands:
|
|
- go version
|
|
- gofmt -l .
|
|
- go vet ./...
|
|
|
|
- name: gosec
|
|
image: golang:1.25
|
|
commands:
|
|
- go install github.com/securego/gosec/v2/cmd/gosec@v2.18.2
|
|
- gosec -fmt text -quiet ./...
|
|
|
|
- name: govulncheck
|
|
image: golang:1.25
|
|
env:
|
|
# REQ-027: offline mode. GOFLAGS=-mod=mod ensures module mode;
|
|
# GOVULNCHECK_DB (when present) overrides the bundled DB.
|
|
GOFLAGS: -mod=mod
|
|
commands:
|
|
- go install golang.org/x/vuln/cmd/govulncheck@v1.1.3
|
|
- govulncheck -mode binary ./...
|
|
|
|
- name: gitleaks
|
|
image: golang:1.25
|
|
commands:
|
|
- apk add --no-cache curl
|
|
- sh -c "$(curl -fsSL https://github.com/gitleaks/gitleaks/releases/latest/download/install.sh)"
|
|
- gitleaks detect --source . --config .gitleaks.toml --baseline-path .gitleaks-baseline.json --no-banner
|
|
|
|
build:
|
|
description: Build the orca binary with version injection
|
|
steps:
|
|
- name: build
|
|
image: golang:1.25
|
|
env:
|
|
VERSION: ${CI_COMMIT_TAG:-dev}
|
|
GIT_COMMIT: ${CI_COMMIT_SHA}
|
|
BUILD_TIME: ${CI_BUILD_TIME}
|
|
commands:
|
|
- |
|
|
LDFLAGS="-s -w \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.version=${VERSION} \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.gitCommit=${GIT_COMMIT} \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.buildTime=${BUILD_TIME}"
|
|
go build -trimpath -ldflags="${LDFLAGS}" -o bin/orca ./cmd/orca
|
|
- file bin/orca
|
|
- ./bin/orca version
|
|
|
|
test:
|
|
description: Run all tests with race detection and coverage (REQ-031)
|
|
steps:
|
|
- name: test
|
|
image: golang:1.25
|
|
commands:
|
|
- go test -race -coverprofile=coverage.out ./...
|
|
- go tool cover -func=coverage.out | tail -1
|
|
|
|
release:
|
|
description: Full release flow — versioned build, tarball, changelog, Gitea release
|
|
when:
|
|
ref: "refs/tags/v*"
|
|
steps:
|
|
- name: build-artifact
|
|
image: golang:1.25
|
|
env:
|
|
VERSION: ${CI_COMMIT_TAG}
|
|
GIT_COMMIT: ${CI_COMMIT_SHA}
|
|
BUILD_TIME: ${CI_BUILD_TIME}
|
|
commands:
|
|
- |
|
|
LDFLAGS="-s -w \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.version=${VERSION} \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.gitCommit=${GIT_COMMIT} \
|
|
-X git.cloudinit.dev/coreci/orca/internal/cli.buildTime=${BUILD_TIME}"
|
|
go build -trimpath -ldflags="${LDFLAGS}" -o bin/orca ./cmd/orca
|
|
- make changelog
|
|
- tar -czf orca-${VERSION}-linux-amd64.tar.gz -C bin orca
|
|
- ls -lh orca-${VERSION}-linux-amd64.tar.gz
|
|
- name: gitea-release
|
|
image: golang:1.25
|
|
env:
|
|
GITEA_TOKEN: ${GITEA_TOKEN}
|
|
VERSION: ${CI_COMMIT_TAG}
|
|
commands:
|
|
- apk add --no-cache curl tar
|
|
- sh -c "$(curl -fsSL https://gitea.com/gitea/tea/releases/latest/download/install.sh)"
|
|
- tea releases create ${VERSION}
|
|
--repo coreci/orca
|
|
--title "Orca ${VERSION}"
|
|
--note-file CHANGELOG.md
|
|
--asset orca-${VERSION}-linux-amd64.tar.gz
|