Skip to content

Upload Trivy findings #182

Upload Trivy findings

Upload Trivy findings #182

Workflow file for this run

name: Basic
on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
schedule:
- cron: "0 16 * * 0" # Every Sunday at 16:00 UTC
workflow_dispatch:
inputs:
deploy_documentation:
description: Deploy documentation
required: false
type: boolean
default: false
env:
CARGO_TERM_COLOR: always
permissions:
contents: read
jobs:
build-and-test:
if: github.event_name != 'schedule'
runs-on: ["oneapi-rs", "Linux"]
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Check if oneAPI is already installed
id: check-oneapi
run: |
if [ -f /home/test-user/intel/oneapi/setvars.sh ]; then
echo "installed=true" >> $GITHUB_OUTPUT
source /home/test-user/intel/oneapi/setvars.sh
# copy envs to github
printenv | grep -E '^(PATH|LD_LIBRARY_PATH|LIBRARY_PATH|CPATH|C_INCLUDE_PATH|CPLUS_INCLUDE_PATH)=' >> $GITHUB_ENV
else
echo "installed=false" >> $GITHUB_OUTPUT
fi
- name: Setup oneAPI
if: steps.check-oneapi.outputs.installed != 'true'
run: |
installer="intel-oneapi-toolkit-2026.1.0.192_offline.sh"
checksum="9d969de9cafbb698bf50f088c4b5174b50fc816f504049e685d6f6d198e10dbc17ef2cd4cfb0bc2b3d2179644a8d77d1"
curl --fail --location --retry 3 --silent --show-error --output "$installer" \
"https://registrationcenter-download.intel.com/akdlm/IRC_NAS/33cb2a22-ddf1-4aa9-8d68-1f5a118acaf2/intel-oneapi-toolkit-2026.1.0.192_offline.sh"
echo "$checksum $installer" | sha384sum --check
sh "./$installer" -a --silent --cli --eula accept
source /home/test-user/intel/oneapi/setvars.sh
# copy envs to github
printenv | grep -E '^(PATH|LD_LIBRARY_PATH|LIBRARY_PATH|CPATH|C_INCLUDE_PATH|CPLUS_INCLUDE_PATH)=' >> $GITHUB_ENV
- name: Print system info
run: |
sycl-ls --verbose
- name: Check formatting
run: cargo fmt --all -- --check
- name: Check C++ formatting
run: |
git ls-files -z -- ':(glob)**/*.cpp' ':(glob)**/*.hpp' ':(glob)**/*.h' \
| xargs -0 --no-run-if-empty clang-format --dry-run --Werror
- name: Run Clippy
run: cargo clippy --workspace --all-targets -- -D warnings
- name: Build
run: cargo build --verbose
- name: Run workspace tests
run: cargo test --workspace --verbose
- name: Run examples
run: |
for example_path in sycl/sycl-rs/examples/*.rs; do
example="$(basename "$example_path" .rs)"
cargo run -p sycl-rs --example "$example" --verbose
done
- name: Generate documentation
run: |
cargo doc -p sycl-rs --no-deps --verbose
cat > target/doc/index.html <<'HTML'
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="refresh" content="0; url=sycl_rs/">
<title>sycl-rs documentation</title>
</head>
<body>
<p><a href="sycl_rs/">sycl-rs documentation</a></p>
</body>
</html>
HTML
- name: Upload documentation artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: documentation
path: target/doc
trivy:
name: Trivy scan
runs-on: ubuntu-latest
permissions:
contents: write
security-events: write
actions: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Generate SPDX SBOM with Trivy
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
scan-type: fs
scan-ref: .
format: spdx-json
output: sbom.spdx.json
- name: Submit SPDX SBOM to GitHub dependency graph
if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
uses: advanced-security/spdx-dependency-submission-action@b009efcf8b9d562a4569d2028c276522232e631f # v0.4.0
with:
filePath: sbom.spdx.json
- name: Scan repository with Trivy
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
scan-type: fs
scan-ref: .
scanners: vuln,secret,misconfig
format: sarif
output: trivy-results.sarif
exit-code: '1'
- name: Upload Trivy findings
if: ${{ always() && hashFiles('trivy-results.sarif') != '' }}
uses: github/codeql-action/upload-sarif@d8073367669608af8fbcc5f63dd0a0d52bb90cff # v4
with:
sarif_file: trivy-results.sarif
category: trivy
deploy-documentation:
if: (github.event_name == 'push' && github.ref == 'refs/heads/main') || (github.event_name == 'workflow_dispatch' && inputs.deploy_documentation == 'true')
needs: build-and-test
runs-on: ubuntu-latest
permissions:
contents: read
pages: write
id-token: write
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: Download documentation artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: documentation
path: target/doc
- name: Configure GitHub Pages
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
- name: Upload documentation to GitHub Pages
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: target/doc
- name: Deploy documentation to GitHub Pages
id: deployment
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0