-
Notifications
You must be signed in to change notification settings - Fork 1
/
.gitlab-ci.yml
63 lines (55 loc) · 1.71 KB
/
.gitlab-ci.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
variables:
SAST_IMAGE_SUFFIX: '-fips'
# You can override the included template(s) by including variable overrides
# SAST customization: https://docs.gitlab.com/ee/user/application_security/sast/#customizing-the-sast-settings
# Secret Detection customization: https://docs.gitlab.com/ee/user/application_security/secret_detection/#customizing-settings
# Dependency Scanning customization: https://docs.gitlab.com/ee/user/application_security/dependency_scanning/#customizing-the-dependency-scanning-settings
# Container Scanning customization: https://docs.gitlab.com/ee/user/application_security/container_scanning/#customizing-the-container-scanning-settings
# Note that environment variables can be set in several places
# See https://docs.gitlab.com/ee/ci/variables/#cicd-variable-precedence
include:
- template: Security/SAST.gitlab-ci.yml
- template: Security/Secret-Detection.gitlab-ci.yml
# - template: Security/Dependency-Scanning.gitlab-ci.yml
- template: Jobs/SAST-IaC.gitlab-ci.yml
image: public.ecr.aws/sam/build-nodejs16.x
stages:
- build
- test
- lint
- unit_test
- vulnerability_test
build:
stage: build
script:
- cat ${testnet_envfile} > .env
- npm install
- npm run compile
artifacts:
untracked: true
sast:
stage: test
lint:
stage: lint
script:
- npm run lint
dependencies:
- build
unit_test:
stage: unit_test
script:
- npm run test
dependencies:
- build
scanner_test:
stage: vulnerability_test
image: alpine:latest
script:
- apk add python3 py3-pip
- apk add --update nodejs npm
- pip3 install slither-analyzer solc-select
- solc-select install 0.8.18
- solc-select use 0.8.18
- npm run slither
dependencies:
- build