diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 16ad0ab06b97b5958895f0ce86cd6c722340cbf7..81f4763438a796a237ee48dcee90f1bc60f60187 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -1,22 +1,6 @@ -# This file is a template, and might need editing before it works on your project. -# To contribute improvements to CI/CD templates, please follow the Development guide at: -# https://docs.gitlab.com/ee/development/cicd/templates.html -# This specific template is located at: -# https://gitlab.com/gitlab-org/gitlab/-/blob/master/lib/gitlab/ci/templates/Getting-Started.gitlab-ci.yml - -# This is a sample GitLab CI/CD configuration file that should run without any modifications. -# It demonstrates a basic 3 stage CI/CD pipeline. Instead of real tests or scripts, -# it uses echo commands to simulate the pipeline execution. -# -# A pipeline is composed of independent jobs that run scripts, grouped into stages. -# Stages run in sequential order, but jobs within stages run in parallel. -# -# For more information, see: https://docs.gitlab.com/ee/ci/yaml/index.html#stages - stages: # List of stages for jobs, and their order of execution - build - test - - analysis - packaging variables: @@ -28,9 +12,6 @@ variables: ARTIFACT_COMPRESSION_LEVEL: "fast" CACHE_COMPRESSION_LEVEL: "fast" # CI_DEBUG_TRACE: "true" - SAST_DEFAULT_ANALYZERS: "spotbugs" - SAST_EXCLUDED_ANALYZERS: "" - SAST_JAVA_VERSION: 11 include: - template: Security/SAST.gitlab-ci.yml @@ -84,54 +65,6 @@ test-job: - ROSETTASDK=$ROSETTASDK make -e check_prerequisites - ROSETTASDK=$ROSETTASDK make -e test -spotbugs-sast: - stage: analysis - variables: - FAIL_NEVER: 1 - tags: - - cmr - artifacts: - paths: - - gl-sast-report.json - rules: - - if: '$CI_PIPELINE_SOURCE == "merge_request_event"' - when: always - - if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS' - when: always - - if: '$CI_COMMIT_BRANCH == "main"' - when: always - - when: manual - allow_failure: true - -secret_detection: - stage: analysis - tags: - - cmr - rules: - - if: '$CI_PIPELINE_SOURCE == "merge_request_event"' - when: always - - if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS' - when: always - - if: '$CI_COMMIT_BRANCH == "main"' - when: always - - when: manual - allow_failure: true - -eslint-sast: - stage: analysis - tags: - - cmr - rules: - - if: '$CI_PIPELINE_SOURCE == "merge_request_event"' - when: always - - if: '$CI_COMMIT_BRANCH && $CI_OPEN_MERGE_REQUESTS' - when: always - - if: '$CI_COMMIT_BRANCH == "main"' - when: always - - when: manual - allow_failure: true - - packaging-job: stage: packaging timeout: 3h