Add verifier process supervisor and broaden analyzer/contracts/effects coverage #954
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Package, consumers, and release qualification | |
| on: | |
| push: | |
| branches: [master] | |
| tags: | |
| - "v*" | |
| pull_request: | |
| branches: ["**"] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| SHARPPROOF_CONTAINER_CPU_LIMIT: 4 | |
| jobs: | |
| security: | |
| name: Exact-SHA security | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| uses: ./.github/workflows/security-reusable.yml | |
| permissions: | |
| contents: read | |
| packages: read | |
| package: | |
| name: Pack exact container artifacts | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| env: | |
| COMPOSE_PROJECT_NAME: sharpproof-package-${{ github.run_id }}-${{ github.run_attempt }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Build the pinned Linux amd64 toolchain | |
| uses: ./.github/actions/build-tooling | |
| - name: Validate release tag and checked-in version in-container | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_SHA | |
| tooling release-tag | |
| - name: Pack, inventory, and validate the exact graph | |
| run: >- | |
| docker compose run --rm tooling pack | |
| -Configuration Release | |
| - name: Upload exact NuGet artifacts | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: artifacts/container-packages/* | |
| if-no-files-found: error | |
| attest: | |
| name: Attest canonical package provenance | |
| if: >- | |
| github.event_name == 'push' && | |
| (github.ref == 'refs/heads/master' || startsWith(github.ref, 'refs/tags/v')) && | |
| github.repository == 'alexyorke/SharpProof' | |
| needs: package | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| attestations: write | |
| artifact-metadata: write | |
| steps: | |
| - name: Download exact NuGet artifacts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Attest package and evidence provenance | |
| uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2 | |
| with: | |
| subject-path: | | |
| nupkgs/*.nupkg | |
| nupkgs/*.snupkg | |
| nupkgs/SharpProof.spdx.json | |
| nupkgs/SharpProof.release.json | |
| nupkgs/SHA256SUMS | |
| - name: Attest package SBOM | |
| uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2 | |
| with: | |
| subject-path: nupkgs/*.nupkg | |
| sbom-path: nupkgs/SharpProof.spdx.json | |
| container-verifier: | |
| name: Canonical Linux analyzer and verifier consumers | |
| needs: package | |
| runs-on: ubuntu-latest | |
| env: | |
| COMPOSE_PROJECT_NAME: sharpproof-consumer-${{ github.run_id }}-${{ github.run_attempt }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Download exact NuGet artifacts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Build the pinned toolchain | |
| uses: ./.github/actions/build-tooling | |
| - name: Run analyzer and real verifier consumers | |
| run: >- | |
| docker compose run --rm tooling package-consumers | |
| -Configuration Release | |
| -PackageSource nupkgs | |
| portable-consumers: | |
| name: Portable exact-package consumer (${{ matrix.os }}) | |
| if: >- | |
| github.event_name == 'push' && | |
| startsWith(github.ref, 'refs/tags/v') && | |
| github.repository == 'alexyorke/SharpProof' | |
| needs: package | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - os: ubuntu-latest | |
| family: linux | |
| - os: windows-latest | |
| family: windows | |
| - os: macos-latest | |
| family: macos | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Run portable-consumer against exact packages | |
| run: >- | |
| pwsh scripts/Test-SharpProofPortableConsumer.ps1 | |
| -PackageSource nupkgs -OsFamily ${{ matrix.family }} | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: portable-receipt-${{ matrix.family }}-${{ github.sha }} | |
| path: artifacts/release-qualification | |
| if-no-files-found: error | |
| release-qualification: | |
| name: Qualify the exact release SHA in-container | |
| if: >- | |
| github.event_name == 'push' && | |
| startsWith(github.ref, 'refs/tags/v') && | |
| github.repository == 'alexyorke/SharpProof' | |
| needs: | |
| - package | |
| - container-verifier | |
| - security | |
| - attest | |
| - portable-consumers | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| env: | |
| COMPOSE_PROJECT_NAME: sharpproof-release-${{ github.run_id }}-${{ github.run_attempt }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Download exact NuGet artifacts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Build the pinned toolchain | |
| uses: ./.github/actions/build-tooling | |
| - name: Require an annotated exact tag in-container | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_SHA | |
| tooling release-tag | |
| - name: Resolve the allowlisted release coverage baseline in-container | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF_NAME -e GITHUB_SHA | |
| tooling release-baseline | |
| - name: Export the container-resolved coverage baseline | |
| run: cat artifacts/release-qualification/coverage.env >> "$GITHUB_ENV" | |
| - name: Run exact-commit acceptance | |
| run: >- | |
| docker compose run --rm tooling acceptance | |
| -Configuration Release | |
| - name: Run exact-commit Debug solution gate | |
| run: >- | |
| docker compose run --rm tooling acceptance | |
| -Configuration Debug | |
| - name: Certify live release configuration | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: >- | |
| pwsh ./scripts/Test-SharpProofReleaseConfiguration.ps1 | |
| -OutputPath artifacts/release-qualification/release-configuration.json | |
| - name: Bind release-configuration receipt | |
| run: >- | |
| pwsh ./scripts/Write-SharpProofQualificationReceipt.ps1 | |
| -Gate release-configuration | |
| -EvidencePath artifacts/release-qualification/release-configuration.json | |
| - name: Download portable OS receipts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| pattern: portable-receipt-*-${{ github.sha }} | |
| path: artifacts/release-qualification | |
| merge-multiple: true | |
| - name: Run exact-commit trusted mutations | |
| run: >- | |
| docker compose run --rm tooling mutation | |
| -Configuration Release | |
| - name: Enforce full release-delta coverage | |
| run: >- | |
| docker compose run --rm | |
| -e SHARPPROOF_COVERAGE_COMPARISON_REF | |
| tooling coverage -Configuration Release | |
| - name: Revalidate downloaded packages with a real proof | |
| run: >- | |
| docker compose run --rm tooling package-consumers | |
| -Configuration Release | |
| -PackageSource nupkgs | |
| - name: Run five exact-package pilots | |
| run: >- | |
| docker compose run --rm tooling pilots | |
| -PackageSource nupkgs | |
| - name: Produce publication dry-run evidence | |
| run: >- | |
| docker compose run --rm tooling release-plan | |
| -PackageSource nupkgs | |
| - name: Bind qualification to container inputs and package hashes | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF_NAME -e GITHUB_SHA | |
| tooling release-qualification -PackageSource nupkgs | |
| - name: Upload exact-SHA qualification evidence | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: always() | |
| with: | |
| name: release-qualification-${{ github.sha }}-${{ github.run_attempt }} | |
| path: artifacts/release-qualification | |
| if-no-files-found: error | |
| retention-days: 90 | |
| publish-private-preview: | |
| name: Promote preview.1 to the private feed | |
| concurrency: | |
| group: sharpproof-publish-${{ github.ref_name }} | |
| cancel-in-progress: false | |
| if: >- | |
| github.event_name == 'push' && | |
| github.ref_name == 'v1.0.0-preview.1' && | |
| github.repository == 'alexyorke/SharpProof' | |
| needs: release-qualification | |
| runs-on: ubuntu-latest | |
| environment: nuget.private-preview | |
| permissions: | |
| contents: read | |
| env: | |
| COMPOSE_PROJECT_NAME: sharpproof-private-${{ github.run_id }}-${{ github.run_attempt }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Validate private-feed configuration | |
| env: | |
| NUGET_PRIVATE_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }} | |
| NUGET_PRIVATE_SOURCE: ${{ vars.NUGET_PRIVATE_SOURCE }} | |
| run: | | |
| test -n "${NUGET_PRIVATE_SOURCE}" | |
| test -n "${NUGET_PRIVATE_API_KEY}" | |
| - name: Build the pinned toolchain | |
| uses: ./.github/actions/build-tooling | |
| - name: Publish already-qualified private-preview bytes in-container | |
| env: | |
| NUGET_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }} | |
| NUGET_READ_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }} | |
| NUGET_SOURCE: ${{ vars.NUGET_PRIVATE_SOURCE }} | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF_NAME -e NUGET_SOURCE -e NUGET_API_KEY -e NUGET_READ_API_KEY | |
| tooling release-publish -PackageSource nupkgs | |
| publish: | |
| name: Promote qualified packages to public NuGet | |
| concurrency: | |
| group: sharpproof-publish-${{ github.ref_name }} | |
| cancel-in-progress: false | |
| if: >- | |
| github.event_name == 'push' && | |
| (github.ref_name == 'v1.0.0-preview.2' || | |
| github.ref_name == 'v1.0.0-rc.1' || | |
| github.ref_name == 'v1.0.0') && | |
| github.repository == 'alexyorke/SharpProof' | |
| needs: release-qualification | |
| runs-on: ubuntu-latest | |
| environment: nuget.org | |
| permissions: | |
| contents: read | |
| id-token: write | |
| env: | |
| COMPOSE_PROJECT_NAME: sharpproof-public-${{ github.run_id }}-${{ github.run_attempt }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }} | |
| path: nupkgs | |
| - name: Validate public-feed configuration | |
| env: | |
| NUGET_USER: ${{ vars.NUGET_USER }} | |
| run: test -n "${NUGET_USER}" | |
| - name: Exchange GitHub OIDC token for a temporary NuGet key | |
| id: nuget-login | |
| uses: NuGet/login@8d196754b4036150537f80ac539e15c2f1028841 # v1 | |
| with: | |
| user: ${{ vars.NUGET_USER }} | |
| - name: Build the pinned toolchain | |
| uses: ./.github/actions/build-tooling | |
| - name: Publish already-qualified package and symbol bytes in-container | |
| env: | |
| NUGET_API_KEY: ${{ steps.nuget-login.outputs.NUGET_API_KEY }} | |
| NUGET_SOURCE: https://api.nuget.org/v3/index.json | |
| run: >- | |
| docker compose run --rm | |
| -e GITHUB_REF_NAME -e NUGET_SOURCE -e NUGET_API_KEY | |
| tooling release-publish -PackageSource nupkgs |