Skip to content
Snippets Groups Projects
Commit 5577bfd7 authored by Andreas Romeyke's avatar Andreas Romeyke
Browse files

- added analysis

parent ac1191f1
No related branches found
No related tags found
No related merge requests found
Pipeline #3145 passed
...@@ -16,6 +16,7 @@ ...@@ -16,6 +16,7 @@
stages: # List of stages for jobs, and their order of execution stages: # List of stages for jobs, and their order of execution
- build - build
- test - test
- analysis
- packaging - packaging
variables: variables:
...@@ -27,6 +28,13 @@ variables: ...@@ -27,6 +28,13 @@ variables:
ARTIFACT_COMPRESSION_LEVEL: "fast" ARTIFACT_COMPRESSION_LEVEL: "fast"
CACHE_COMPRESSION_LEVEL: "fast" CACHE_COMPRESSION_LEVEL: "fast"
# CI_DEBUG_TRACE: "true" # CI_DEBUG_TRACE: "true"
SAST_DEFAULT_ANALYZERS: "spotbugs"
SAST_EXCLUDED_ANALYZERS: ""
SAST_JAVA_VERSION: 11
include:
- template: Security/SAST.gitlab-ci.yml
- template: Security/Secret-Detection.gitlab-ci.yml
default: default:
image: image:
...@@ -76,6 +84,53 @@ test-job: ...@@ -76,6 +84,53 @@ test-job:
- ROSETTASDK=$ROSETTASDK make -e check_prerequisites - ROSETTASDK=$ROSETTASDK make -e check_prerequisites
- ROSETTASDK=$ROSETTASDK make -e test - ROSETTASDK=$ROSETTASDK make -e test
spotbugs-sast:
stage: analysis
variables:
FAIL_NEVER: 1
tags:
- cmr
artifacts:
paths:
- gl-sast-report.json
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
when: always
- if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS'
when: always
- if: '$CI_COMMIT_BRANCH == "main"'
when: always
- when: manual
allow_failure: true
secret_detection:
stage: analysis
tags:
- cmr
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
when: always
- if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS'
when: always
- if: '$CI_COMMIT_BRANCH == "main"'
when: always
- when: manual
allow_failure: true
eslint-sast:
stage: analysis
tags:
- cmr
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
when: always
- if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS'
when: always
- if: '$CI_COMMIT_BRANCH == "main"'
when: always
- when: manual
allow_failure: true
packaging-job: packaging-job:
stage: packaging stage: packaging
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment