Skip to content

Fixed: dependency build scripts #6

Fixed: dependency build scripts

Fixed: dependency build scripts #6

# Vorbedingung:
# - Die Conan-Lockdatei (conan_linux_x86_64.lock) muss existieren.
name: Build and Test for Linux x86_64
on:
push:
branches: [ "main", "v1*", "v2*", "v3*" ]
pull_request:
branches: [ "main", "v1*", "v2*", "v3*" ]
jobs:
# Bereitet die Abhängigkeiten für Linux x86_64 vor.
# Dies ist ein separater Job, da dies sehr lange dauern (30-60 Min, falls alles gebaut werden muss) kann und das Ergebnis gecached werden soll, auch wenn das Bauen später fehlschlägt.
build_dependencies_pc:
runs-on: CPR_Ubuntu2404
timeout-minutes: 90
steps:
- uses: actions/checkout@v7
- uses: CommonplaceRobotics/Action_Build_Conan_Dependencies/Linux_x86_64@v2
with:
lockfile: 'conan_linux_x86_64.lock'
cache_key: conan-${{ runner.os }}-x86_64-${{ hashFiles('**/conan_linux_x86_64.lock', '**/conanfile.py') }}
# Build and run tests for Linux x86_64
test:
#runs-on: ubuntu-latest
runs-on: CPR_Ubuntu2404
timeout-minutes: 15
needs: build_dependencies_pc
steps:
- uses: actions/checkout@v7
- name: Restore cached dependencies
id: cache
uses: actions/cache/restore@v5
with:
path: |
~/.conan2
out
key: conan-${{ runner.os }}-x86_64-${{ hashFiles('conan_linux_x86_64.lock', 'conanfile.py') }}
fail-on-cache-miss: true
- name: Install Conan
uses: conan-io/setup-conan@v1
- name: Configure CMake
run: |
rm -f CMakePresets.json
echo "{\"version\": 4,\"include\":[\"out/conan/Linux/x86_64/Release/generators/CMakePresets.json\"]}" >> CMakePresets.json
cmake --preset conan-linux-x86_64-release
- name: Build Tests (x86_64)
run: |
cd out/build/Linux/x86_64/Release
cmake --build . --target iRCApp_Tests
- name: Run Tests
run: |
cd out/build/Linux/x86_64/Release
./iRCApp_Tests
- name: Rename Library
run: mv out/build/Linux/x86_64/Release/libiRCApp.a out/build/Linux/x86_64/Release/libiRCApp_x86_64.a
- name: Export Library
uses: actions/upload-artifact@v7
with:
name: libiRCApp_x86_64.a
path: out/build/Linux/x86_64/Release/libiRCApp_x86_64.a
archive: false
# Creates the SBOM and checks its compliance
sbom:
runs-on: ubuntu-latest
timeout-minutes: 15
needs: test
steps:
- uses: actions/checkout@v7
- name: Restore cached dependencies
id: cache
uses: actions/cache/restore@v5
with:
path: |
~/.conan2
out
key: conan-${{ runner.os }}-x86_64-${{ hashFiles('conan_linux_x86_64.lock', 'conanfile.py') }}
fail-on-cache-miss: true
# This generates sbomify.json with lifecycle info
- name: Configure CMake
run: |
rm -f CMakePresets.json
echo "{\"version\": 4,\"include\":[\"out/conan/Linux/x86_64/Release/generators/CMakePresets.json\"]}" >> CMakePresets.json
cmake --preset conan-linux-x86_64-release
mv out/build/Linux/x86_64/Release/sbomify.json .
# We need the library to calculate its hash
- name: Import Library
uses: actions/download-artifact@v8
with:
name: libiRCApp_x86_64.a
path: out/build/Linux/x86_64/Release
- name: Rename Library
run: mv out/build/Linux/x86_64/Release/libiRCApp_x86_64.a out/build/Linux/x86_64/Release/libiRCApp.a
# Liest die Core-Version aus CMakeLists.txt
- name: Get software version
run: |
VER=`grep -E -o "VERSION[[:blank:]]+[[:digit:]]+\.[[:digit:]]+\.[[:digit:]]+" CMakeLists.txt | sed "s/[^0-9.]*//g"`
echo "Software version '$VER' detected"
echo "SW_VERSION=$VER" >> $GITHUB_ENV
- name: Create incomplete SBOM
uses: CommonplaceRobotics/Action_Create_Conan_SBOM@v4
with:
lockfile: conan_linux_rpi.lock
sbom: sbom_temp1.cdx.json
conan_params: '--profile=cpr_linux_x86_64_release'
- name: Enrich and Augment SBOM
uses: sbomify/sbomify-action@master
env:
SBOM_FILE: sbom_temp1.cdx.json
OUTPUT_FILE: sbom_temp2.cdx.json
COMPONENT_NAME: AppAPI_CPP
COMPONENT_VERSION: ${{ env.SW_VERSION }}
# Produkt- und Firmeninfo werden aus sbomify.json geladen
AUGMENT: true
# Metadaten aus Paket-Registry hinzufügen
ENRICH: true
# Metadaten aus additional_packages_rpi.txt hinzufügen
ADDITIONAL_PACKAGES_FILE: additional_packages_rpi.txt
UPLOAD: false
- name: Final SBOM enrichment
uses: CommonplaceRobotics/Action_SBOM_Enrichment@v9
with:
database: .github/workflows/sbom_enrichment_db.json
sbom: sbom_temp2.cdx.json
sbom_out: sbom_linux_x86_64.cdx.json
cmake_build_dir: out/build/Linux/x86_64/Release
- name: Export SBOM
uses: actions/upload-artifact@v7
with:
path: sbom_linux_x86_64.cdx.json
archive: false
- name: Validate SBOM with company policies
uses: CommonplaceRobotics/SW_Validate_SBOM@v6
with:
sbom: sbom_linux_x86_64.cdx.json