mirror of
https://github.com/gradle/actions.git
synced 2025-11-26 17:09:10 +08:00
Compare commits
312 Commits
v3.1.0
...
v4.0.0-bet
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
833b05f3e6 | ||
|
|
06905c7a0f | ||
|
|
73f1290de7 | ||
|
|
b6395da67c | ||
|
|
ce4c3a6c5e | ||
|
|
b644be617f | ||
|
|
7179909719 | ||
|
|
c01aea0cb4 | ||
|
|
479297d73e | ||
|
|
fe594a580d | ||
|
|
53f2a5657b | ||
|
|
fd87365911 | ||
|
|
c3f989640d | ||
|
|
6c9e547314 | ||
|
|
1a11891cfe | ||
|
|
fae6382622 | ||
|
|
81b4ac7741 | ||
|
|
c9872874b0 | ||
|
|
561dcd8516 | ||
|
|
7bb45b1dbd | ||
|
|
dc97151e55 | ||
|
|
2289da045c | ||
|
|
40a3605597 | ||
|
|
e6688f31b8 | ||
|
|
46308b920a | ||
|
|
7387edbbb3 | ||
|
|
9e459adb11 | ||
|
|
1371d49f1d | ||
|
|
8e4868ab4a | ||
|
|
5acdee61f0 | ||
|
|
32f9239e2c | ||
|
|
12cb23c359 | ||
|
|
238a3da6f4 | ||
|
|
2041ce6ab1 | ||
|
|
ded8009fcf | ||
|
|
db8e69bc03 | ||
|
|
4b56f19bda | ||
|
|
4576973cce | ||
|
|
5d7c18409c | ||
|
|
7da993afd5 | ||
|
|
de6862d826 | ||
|
|
4c453aec59 | ||
|
|
917439d87d | ||
|
|
77266ec345 | ||
|
|
514ac344fc | ||
|
|
f8aa3ed8b4 | ||
|
|
b175189376 | ||
|
|
20e923b8cb | ||
|
|
e7f9f25d86 | ||
|
|
f8f7d3e704 | ||
|
|
7a630bc41b | ||
|
|
a77cb2b0f8 | ||
|
|
54f7dc55a5 | ||
|
|
579a013225 | ||
|
|
94355bbb2f | ||
|
|
6d20c16462 | ||
|
|
b7e399239c | ||
|
|
723ca4de01 | ||
|
|
72dde7ef1e | ||
|
|
3083f01451 | ||
|
|
27dea2df09 | ||
|
|
91a526b647 | ||
|
|
d92de28b80 | ||
|
|
8d318190ad | ||
|
|
a025cbe7ec | ||
|
|
23dad2b1c7 | ||
|
|
4a315dceb2 | ||
|
|
bb7a843511 | ||
|
|
9a57bcca96 | ||
|
|
22818445b3 | ||
|
|
36c24e793d | ||
|
|
dff3ef9b8d | ||
|
|
01254b3eaa | ||
|
|
d9c87d481d | ||
|
|
ff865cb801 | ||
|
|
c3acd19a4a | ||
|
|
e5bbd4c742 | ||
|
|
d7cd9fc65c | ||
|
|
6407986e96 | ||
|
|
87bf5ca2ea | ||
|
|
81b4ece56a | ||
|
|
cdbbabd09c | ||
|
|
dad038d88d | ||
|
|
621f3b3f79 | ||
|
|
4022faad7e | ||
|
|
95ef72241e | ||
|
|
169bec5d8b | ||
|
|
b9abb7b195 | ||
|
|
c04155e2ca | ||
|
|
1da1cc97d5 | ||
|
|
c401249391 | ||
|
|
a6a0c7dcef | ||
|
|
3f3913eed0 | ||
|
|
2cd2a6e951 | ||
|
|
dbbdc275be | ||
|
|
ae74429826 | ||
|
|
bdc7162ff9 | ||
|
|
31ae3562f6 | ||
|
|
719985db3d | ||
|
|
b53238971c | ||
|
|
5f1c5827bf | ||
|
|
d9336dac04 | ||
|
|
8dbe9a3802 | ||
|
|
9c3430720d | ||
|
|
30c82f0068 | ||
|
|
e3bc05f224 | ||
|
|
485ea107b7 | ||
|
|
c1091c9c8e | ||
|
|
d0a116fff5 | ||
|
|
e238a7ad22 | ||
|
|
1d2ea6e5a8 | ||
|
|
114c1c234e | ||
|
|
2db3ae936e | ||
|
|
a68381d359 | ||
|
|
52ae27f7bb | ||
|
|
d1cd62d80a | ||
|
|
af6e576724 | ||
|
|
775b4d10d7 | ||
|
|
30610bc983 | ||
|
|
d4d72c9934 | ||
|
|
96b9cb4988 | ||
|
|
db270b9337 | ||
|
|
d91e2960eb | ||
|
|
0498421560 | ||
|
|
edb13383f3 | ||
|
|
cd560aa3ad | ||
|
|
500e0ee5b3 | ||
|
|
eb13cf7170 | ||
|
|
ea14aa9caf | ||
|
|
063cfaf0eb | ||
|
|
35f9242e22 | ||
|
|
90f1de0556 | ||
|
|
da512b52a5 | ||
|
|
db19848a5f | ||
|
|
941b289d84 | ||
|
|
bce7daca54 | ||
|
|
11eaed9738 | ||
|
|
cd62d9c9ef | ||
|
|
a54fb6a5bb | ||
|
|
ef36f81b41 | ||
|
|
18998bc43e | ||
|
|
a772c14b33 | ||
|
|
7763d71170 | ||
|
|
9ab93ee864 | ||
|
|
d124ec149f | ||
|
|
6ccde15122 | ||
|
|
750cdda3ed | ||
|
|
c198d84863 | ||
|
|
d211a39090 | ||
|
|
439ed0a0ac | ||
|
|
eef9b10930 | ||
|
|
8be796e9fa | ||
|
|
3c2d3b6f2a | ||
|
|
0fa10b26b8 | ||
|
|
6cec5d49d4 | ||
|
|
6d55902761 | ||
|
|
0325d99e52 | ||
|
|
d0f2f0387e | ||
|
|
248dd904ed | ||
|
|
d576690f96 | ||
|
|
feb10e7858 | ||
|
|
5893d44739 | ||
|
|
fb14e0ee5b | ||
|
|
0261d93071 | ||
|
|
6e48e8e40c | ||
|
|
b855ea8d07 | ||
|
|
7d97cfadb0 | ||
|
|
5eedb47e5a | ||
|
|
3e6b0e422f | ||
|
|
ebf9707dff | ||
|
|
0627979b9c | ||
|
|
fcf9eeaf01 | ||
|
|
713dee76c6 | ||
|
|
1fd792382e | ||
|
|
38e549269f | ||
|
|
e9d1819b96 | ||
|
|
62557f3635 | ||
|
|
33741bd2bb | ||
|
|
ea328a863d | ||
|
|
ba79f71e36 | ||
|
|
1c25312b02 | ||
|
|
3a234be20e | ||
|
|
c1a61df4f1 | ||
|
|
fa4107aefb | ||
|
|
39cecc54d0 | ||
|
|
f1476a710d | ||
|
|
3252e655d0 | ||
|
|
be0b7f44a7 | ||
|
|
c31cff66cf | ||
|
|
0f427bc07b | ||
|
|
30a2ee13f2 | ||
|
|
d37a479015 | ||
|
|
3e155e3d92 | ||
|
|
ffea2635eb | ||
|
|
e21decc9db | ||
|
|
6832731061 | ||
|
|
87f10dd82f | ||
|
|
acdd37d76d | ||
|
|
a66014f771 | ||
|
|
4ccff7d80f | ||
|
|
5e5501accb | ||
|
|
b2fd266e89 | ||
|
|
0be451eca3 | ||
|
|
7b822e51a5 | ||
|
|
60be407ece | ||
|
|
9e47918adf | ||
|
|
b64dafb1c9 | ||
|
|
6a8b99d4b5 | ||
|
|
153b1135d0 | ||
|
|
211d342ee6 | ||
|
|
6599acbe46 | ||
|
|
e7c0080dc5 | ||
|
|
0979245ebd | ||
|
|
73638aa351 | ||
|
|
d28f25d60a | ||
|
|
8bac4a819c | ||
|
|
bd3d4b0246 | ||
|
|
667e034cd9 | ||
|
|
cd54673221 | ||
|
|
0ebfbb8f41 | ||
|
|
9169d36880 | ||
|
|
63fcfbfe27 | ||
|
|
47fb100300 | ||
|
|
1824c01ad8 | ||
|
|
dec6c472c1 | ||
|
|
aeb3156e6f | ||
|
|
7e9e469530 | ||
|
|
9d0de74673 | ||
|
|
2e02e6624e | ||
|
|
c9822ff527 | ||
|
|
cfe478af6a | ||
|
|
92975d7f32 | ||
|
|
e235596c88 | ||
|
|
6232a3f503 | ||
|
|
8ffe734df6 | ||
|
|
59a5222069 | ||
|
|
498f0e409b | ||
|
|
3335c16182 | ||
|
|
528fe78d31 | ||
|
|
ecf84edd45 | ||
|
|
220951bf17 | ||
|
|
c93523a078 | ||
|
|
0ac212a9d2 | ||
|
|
2b3c9df6d2 | ||
|
|
dd32675981 | ||
|
|
a9dc5dee4e | ||
|
|
dbdb67aa6c | ||
|
|
8691214514 | ||
|
|
1105cf252a | ||
|
|
ab471b0c20 | ||
|
|
90bf65c87c | ||
|
|
38a821729e | ||
|
|
627fa7627c | ||
|
|
e40c718900 | ||
|
|
19d422aa4b | ||
|
|
d6f94a4073 | ||
|
|
b7ef93c7b7 | ||
|
|
cfd20ecc0a | ||
|
|
ed4d086d37 | ||
|
|
ebf4d13461 | ||
|
|
4214607904 | ||
|
|
d71ecafebf | ||
|
|
1d19edabdc | ||
|
|
4057bfe59d | ||
|
|
1390ca6454 | ||
|
|
a3f366ddb7 | ||
|
|
340a6438d0 | ||
|
|
a1a85e9819 | ||
|
|
0b06ce12c8 | ||
|
|
e24011a3b5 | ||
|
|
eb261d5636 | ||
|
|
875d13660f | ||
|
|
a5a8ae9361 | ||
|
|
5fe1aec3c1 | ||
|
|
7be6c56c3d | ||
|
|
7e87a5e8d9 | ||
|
|
518b14b196 | ||
|
|
81b3a2db60 | ||
|
|
195c67f931 | ||
|
|
5a171ce5b8 | ||
|
|
5512434733 | ||
|
|
faecef076b | ||
|
|
50af102149 | ||
|
|
cc54166e15 | ||
|
|
12646f8198 | ||
|
|
c276584302 | ||
|
|
393df4bfa2 | ||
|
|
7c03a8d3fb | ||
|
|
e562ae9f4a | ||
|
|
0dfb0395f5 | ||
|
|
8735d0c1bb | ||
|
|
a6050d4c14 | ||
|
|
ef7196c315 | ||
|
|
60b8089f55 | ||
|
|
9b415aef98 | ||
|
|
3fe876afb8 | ||
|
|
f4c37be1e8 | ||
|
|
68b69be9d4 | ||
|
|
f8d50e3e2b | ||
|
|
07f64e2534 | ||
|
|
cee9fbd6e2 | ||
|
|
32f1033fd2 | ||
|
|
7b589d9740 | ||
|
|
f58a414c4f | ||
|
|
e43d10f419 | ||
|
|
579fbbe722 | ||
|
|
b00d9dd511 | ||
|
|
f091a59e67 | ||
|
|
6800f3450a | ||
|
|
9e899d11ad | ||
|
|
acc4561424 | ||
|
|
e2b14c9dfc |
8
.github/actions/build-dist/action.yml
vendored
8
.github/actions/build-dist/action.yml
vendored
@@ -6,6 +6,8 @@ runs:
|
|||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: 20
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
cache-dependency-path: sources/package-lock.json
|
||||||
- name: Build distribution
|
- name: Build distribution
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -14,6 +16,12 @@ runs:
|
|||||||
npm install
|
npm install
|
||||||
npm run build
|
npm run build
|
||||||
working-directory: sources
|
working-directory: sources
|
||||||
|
|
||||||
|
- name: Copy the generated sources/dist directory to the top-level dist
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
cp -r sources/dist .
|
||||||
|
|
||||||
- name: Upload distribution
|
- name: Upload distribution
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
12
.github/actions/download-dist/action.yml
vendored
12
.github/actions/download-dist/action.yml
vendored
@@ -1,12 +0,0 @@
|
|||||||
name: 'Download dist'
|
|
||||||
# Downloads a 'dist' directory artifact that was uploaded in an earlier step
|
|
||||||
# We control this with an environment variable to allow for easier global configuration.
|
|
||||||
runs:
|
|
||||||
using: "composite"
|
|
||||||
steps:
|
|
||||||
- name: Download dist
|
|
||||||
if: ${{ env.DOWNLOAD_DIST == 'true' }}
|
|
||||||
uses: actions/download-artifact@v4
|
|
||||||
with:
|
|
||||||
name: dist
|
|
||||||
path: dist/
|
|
||||||
23
.github/actions/init-integ-test/action.yml
vendored
Normal file
23
.github/actions/init-integ-test/action.yml
vendored
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
name: 'Initialize integ-test'
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: "composite"
|
||||||
|
steps:
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: 'temurin'
|
||||||
|
java-version: 11
|
||||||
|
|
||||||
|
- name: Configure environment
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "ALLOWED_GRADLE_WRAPPER_CHECKSUMS=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
|
# Downloads a 'dist' directory artifact that was uploaded in an earlier 'build-dist' step
|
||||||
|
- name: Download dist
|
||||||
|
if: ${{ env.SKIP_DIST != 'true' && !env.ACT }}
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: dist
|
||||||
|
path: dist/
|
||||||
33
.github/dependabot.yml
vendored
33
.github/dependabot.yml
vendored
@@ -6,6 +6,15 @@ registries:
|
|||||||
username: dummy # Required by dependabot
|
username: dummy # Required by dependabot
|
||||||
password: dummy # Required by dependabot
|
password: dummy # Required by dependabot
|
||||||
updates:
|
updates:
|
||||||
|
- package-ecosystem: "npm"
|
||||||
|
directory: "/sources"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
groups:
|
||||||
|
npm-dependencies:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|
||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
@@ -14,19 +23,25 @@ updates:
|
|||||||
github-actions:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
|
# github-actions with directory: "/" only monitors .github/workflows
|
||||||
- package-ecosystem: "npm"
|
# https://github.com/dependabot/dependabot-core/issues/6345
|
||||||
directory: "/"
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/.github/actions/build-dist"
|
||||||
schedule:
|
schedule:
|
||||||
interval: "weekly"
|
interval: "weekly"
|
||||||
ignore:
|
|
||||||
- dependency-name: "@types/node" # Breaking change: update with next major release
|
|
||||||
- dependency-name: "@octokit/rest" # Tied to node version
|
|
||||||
groups:
|
groups:
|
||||||
npm-dependencies:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/.github/actions/init-integ-test"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|
||||||
- package-ecosystem: "gradle"
|
- package-ecosystem: "gradle"
|
||||||
directory: ".github/workflow-samples/gradle-plugin"
|
directory: ".github/workflow-samples/gradle-plugin"
|
||||||
registries:
|
registries:
|
||||||
|
|||||||
Binary file not shown.
@@ -1,7 +1,7 @@
|
|||||||
distributionBase=GRADLE_USER_HOME
|
distributionBase=GRADLE_USER_HOME
|
||||||
distributionPath=wrapper/dists
|
distributionPath=wrapper/dists
|
||||||
distributionSha256Sum=9d926787066a081739e8200858338b4a69e837c3a821a33aca9db09dd4a41026
|
distributionSha256Sum=d725d707bfabd4dfdc958c624003b3c80accc03f7037b5122c4b1d0ef15cecab
|
||||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
distributionUrl=https\://services.gradle.org/distributions/gradle-8.9-bin.zip
|
||||||
networkTimeout=10000
|
networkTimeout=10000
|
||||||
validateDistributionUrl=true
|
validateDistributionUrl=true
|
||||||
zipStoreBase=GRADLE_USER_HOME
|
zipStoreBase=GRADLE_USER_HOME
|
||||||
|
|||||||
@@ -15,6 +15,8 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
#
|
#
|
||||||
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
|
#
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#
|
#
|
||||||
@@ -55,7 +57,7 @@
|
|||||||
# Darwin, MinGW, and NonStop.
|
# Darwin, MinGW, and NonStop.
|
||||||
#
|
#
|
||||||
# (3) This script is generated from the Groovy template
|
# (3) This script is generated from the Groovy template
|
||||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||||
# within the Gradle project.
|
# within the Gradle project.
|
||||||
#
|
#
|
||||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||||
@@ -84,7 +86,8 @@ done
|
|||||||
# shellcheck disable=SC2034
|
# shellcheck disable=SC2034
|
||||||
APP_BASE_NAME=${0##*/}
|
APP_BASE_NAME=${0##*/}
|
||||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s
|
||||||
|
' "$PWD" ) || exit
|
||||||
|
|
||||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||||
MAX_FD=maximum
|
MAX_FD=maximum
|
||||||
|
|||||||
@@ -13,6 +13,8 @@
|
|||||||
@rem See the License for the specific language governing permissions and
|
@rem See the License for the specific language governing permissions and
|
||||||
@rem limitations under the License.
|
@rem limitations under the License.
|
||||||
@rem
|
@rem
|
||||||
|
@rem SPDX-License-Identifier: Apache-2.0
|
||||||
|
@rem
|
||||||
|
|
||||||
@if "%DEBUG%"=="" @echo off
|
@if "%DEBUG%"=="" @echo off
|
||||||
@rem ##########################################################################
|
@rem ##########################################################################
|
||||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
|||||||
%JAVA_EXE% -version >NUL 2>&1
|
%JAVA_EXE% -version >NUL 2>&1
|
||||||
if %ERRORLEVEL% equ 0 goto execute
|
if %ERRORLEVEL% equ 0 goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
@@ -57,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
|||||||
|
|
||||||
if exist "%JAVA_EXE%" goto execute
|
if exist "%JAVA_EXE%" goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
|
|||||||
Binary file not shown.
@@ -1,7 +1,7 @@
|
|||||||
distributionBase=GRADLE_USER_HOME
|
distributionBase=GRADLE_USER_HOME
|
||||||
distributionPath=wrapper/dists
|
distributionPath=wrapper/dists
|
||||||
distributionSha256Sum=9d926787066a081739e8200858338b4a69e837c3a821a33aca9db09dd4a41026
|
distributionSha256Sum=d725d707bfabd4dfdc958c624003b3c80accc03f7037b5122c4b1d0ef15cecab
|
||||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
distributionUrl=https\://services.gradle.org/distributions/gradle-8.9-bin.zip
|
||||||
networkTimeout=10000
|
networkTimeout=10000
|
||||||
validateDistributionUrl=true
|
validateDistributionUrl=true
|
||||||
zipStoreBase=GRADLE_USER_HOME
|
zipStoreBase=GRADLE_USER_HOME
|
||||||
|
|||||||
7
.github/workflow-samples/groovy-dsl/gradlew
vendored
7
.github/workflow-samples/groovy-dsl/gradlew
vendored
@@ -15,6 +15,8 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
#
|
#
|
||||||
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
|
#
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#
|
#
|
||||||
@@ -55,7 +57,7 @@
|
|||||||
# Darwin, MinGW, and NonStop.
|
# Darwin, MinGW, and NonStop.
|
||||||
#
|
#
|
||||||
# (3) This script is generated from the Groovy template
|
# (3) This script is generated from the Groovy template
|
||||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||||
# within the Gradle project.
|
# within the Gradle project.
|
||||||
#
|
#
|
||||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||||
@@ -84,7 +86,8 @@ done
|
|||||||
# shellcheck disable=SC2034
|
# shellcheck disable=SC2034
|
||||||
APP_BASE_NAME=${0##*/}
|
APP_BASE_NAME=${0##*/}
|
||||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s
|
||||||
|
' "$PWD" ) || exit
|
||||||
|
|
||||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||||
MAX_FD=maximum
|
MAX_FD=maximum
|
||||||
|
|||||||
22
.github/workflow-samples/groovy-dsl/gradlew.bat
vendored
22
.github/workflow-samples/groovy-dsl/gradlew.bat
vendored
@@ -13,6 +13,8 @@
|
|||||||
@rem See the License for the specific language governing permissions and
|
@rem See the License for the specific language governing permissions and
|
||||||
@rem limitations under the License.
|
@rem limitations under the License.
|
||||||
@rem
|
@rem
|
||||||
|
@rem SPDX-License-Identifier: Apache-2.0
|
||||||
|
@rem
|
||||||
|
|
||||||
@if "%DEBUG%"=="" @echo off
|
@if "%DEBUG%"=="" @echo off
|
||||||
@rem ##########################################################################
|
@rem ##########################################################################
|
||||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
|||||||
%JAVA_EXE% -version >NUL 2>&1
|
%JAVA_EXE% -version >NUL 2>&1
|
||||||
if %ERRORLEVEL% equ 0 goto execute
|
if %ERRORLEVEL% equ 0 goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
@@ -57,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
|||||||
|
|
||||||
if exist "%JAVA_EXE%" goto execute
|
if exist "%JAVA_EXE%" goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
|
|||||||
@@ -1,13 +1,12 @@
|
|||||||
plugins {
|
plugins {
|
||||||
id "com.gradle.enterprise" version "3.16.2"
|
id "com.gradle.develocity" version "3.17.6"
|
||||||
id "com.gradle.common-custom-user-data-gradle-plugin" version "1.12.1"
|
id "com.gradle.common-custom-user-data-gradle-plugin" version "2.0.1"
|
||||||
}
|
}
|
||||||
|
|
||||||
gradleEnterprise {
|
develocity {
|
||||||
buildScan {
|
buildScan {
|
||||||
termsOfServiceUrl = "https://gradle.com/terms-of-service"
|
termsOfUseUrl = "https://gradle.com/help/legal-terms-of-use"
|
||||||
termsOfServiceAgree = "yes"
|
termsOfUseAgree = "yes"
|
||||||
publishAlways()
|
|
||||||
uploadInBackground = false
|
uploadInBackground = false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
@@ -1,7 +1,7 @@
|
|||||||
distributionBase=GRADLE_USER_HOME
|
distributionBase=GRADLE_USER_HOME
|
||||||
distributionPath=wrapper/dists
|
distributionPath=wrapper/dists
|
||||||
distributionSha256Sum=9d926787066a081739e8200858338b4a69e837c3a821a33aca9db09dd4a41026
|
distributionSha256Sum=d725d707bfabd4dfdc958c624003b3c80accc03f7037b5122c4b1d0ef15cecab
|
||||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
distributionUrl=https\://services.gradle.org/distributions/gradle-8.9-bin.zip
|
||||||
networkTimeout=10000
|
networkTimeout=10000
|
||||||
validateDistributionUrl=true
|
validateDistributionUrl=true
|
||||||
zipStoreBase=GRADLE_USER_HOME
|
zipStoreBase=GRADLE_USER_HOME
|
||||||
|
|||||||
@@ -15,6 +15,8 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
#
|
#
|
||||||
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
|
#
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#
|
#
|
||||||
@@ -55,7 +57,7 @@
|
|||||||
# Darwin, MinGW, and NonStop.
|
# Darwin, MinGW, and NonStop.
|
||||||
#
|
#
|
||||||
# (3) This script is generated from the Groovy template
|
# (3) This script is generated from the Groovy template
|
||||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||||
# within the Gradle project.
|
# within the Gradle project.
|
||||||
#
|
#
|
||||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||||
@@ -84,7 +86,8 @@ done
|
|||||||
# shellcheck disable=SC2034
|
# shellcheck disable=SC2034
|
||||||
APP_BASE_NAME=${0##*/}
|
APP_BASE_NAME=${0##*/}
|
||||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s
|
||||||
|
' "$PWD" ) || exit
|
||||||
|
|
||||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||||
MAX_FD=maximum
|
MAX_FD=maximum
|
||||||
|
|||||||
@@ -13,6 +13,8 @@
|
|||||||
@rem See the License for the specific language governing permissions and
|
@rem See the License for the specific language governing permissions and
|
||||||
@rem limitations under the License.
|
@rem limitations under the License.
|
||||||
@rem
|
@rem
|
||||||
|
@rem SPDX-License-Identifier: Apache-2.0
|
||||||
|
@rem
|
||||||
|
|
||||||
@if "%DEBUG%"=="" @echo off
|
@if "%DEBUG%"=="" @echo off
|
||||||
@rem ##########################################################################
|
@rem ##########################################################################
|
||||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
|||||||
%JAVA_EXE% -version >NUL 2>&1
|
%JAVA_EXE% -version >NUL 2>&1
|
||||||
if %ERRORLEVEL% equ 0 goto execute
|
if %ERRORLEVEL% equ 0 goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
@@ -57,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
|||||||
|
|
||||||
if exist "%JAVA_EXE%" goto execute
|
if exist "%JAVA_EXE%" goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
|
|||||||
@@ -8,9 +8,9 @@ repositories {
|
|||||||
|
|
||||||
dependencies {
|
dependencies {
|
||||||
api("org.apache.commons:commons-math3:3.6.1")
|
api("org.apache.commons:commons-math3:3.6.1")
|
||||||
implementation("com.google.guava:guava:33.0.0-jre")
|
implementation("com.google.guava:guava:33.2.1-jre")
|
||||||
|
|
||||||
testImplementation("org.junit.jupiter:junit-jupiter:5.10.2")
|
testImplementation("org.junit.jupiter:junit-jupiter:5.10.3")
|
||||||
}
|
}
|
||||||
|
|
||||||
tasks.test {
|
tasks.test {
|
||||||
|
|||||||
Binary file not shown.
@@ -1,7 +1,7 @@
|
|||||||
distributionBase=GRADLE_USER_HOME
|
distributionBase=GRADLE_USER_HOME
|
||||||
distributionPath=wrapper/dists
|
distributionPath=wrapper/dists
|
||||||
distributionSha256Sum=9d926787066a081739e8200858338b4a69e837c3a821a33aca9db09dd4a41026
|
distributionSha256Sum=d725d707bfabd4dfdc958c624003b3c80accc03f7037b5122c4b1d0ef15cecab
|
||||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
distributionUrl=https\://services.gradle.org/distributions/gradle-8.9-bin.zip
|
||||||
networkTimeout=10000
|
networkTimeout=10000
|
||||||
validateDistributionUrl=true
|
validateDistributionUrl=true
|
||||||
zipStoreBase=GRADLE_USER_HOME
|
zipStoreBase=GRADLE_USER_HOME
|
||||||
|
|||||||
7
.github/workflow-samples/kotlin-dsl/gradlew
vendored
7
.github/workflow-samples/kotlin-dsl/gradlew
vendored
@@ -15,6 +15,8 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
#
|
#
|
||||||
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
|
#
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#
|
#
|
||||||
@@ -55,7 +57,7 @@
|
|||||||
# Darwin, MinGW, and NonStop.
|
# Darwin, MinGW, and NonStop.
|
||||||
#
|
#
|
||||||
# (3) This script is generated from the Groovy template
|
# (3) This script is generated from the Groovy template
|
||||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||||
# within the Gradle project.
|
# within the Gradle project.
|
||||||
#
|
#
|
||||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||||
@@ -84,7 +86,8 @@ done
|
|||||||
# shellcheck disable=SC2034
|
# shellcheck disable=SC2034
|
||||||
APP_BASE_NAME=${0##*/}
|
APP_BASE_NAME=${0##*/}
|
||||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s
|
||||||
|
' "$PWD" ) || exit
|
||||||
|
|
||||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||||
MAX_FD=maximum
|
MAX_FD=maximum
|
||||||
|
|||||||
22
.github/workflow-samples/kotlin-dsl/gradlew.bat
vendored
22
.github/workflow-samples/kotlin-dsl/gradlew.bat
vendored
@@ -13,6 +13,8 @@
|
|||||||
@rem See the License for the specific language governing permissions and
|
@rem See the License for the specific language governing permissions and
|
||||||
@rem limitations under the License.
|
@rem limitations under the License.
|
||||||
@rem
|
@rem
|
||||||
|
@rem SPDX-License-Identifier: Apache-2.0
|
||||||
|
@rem
|
||||||
|
|
||||||
@if "%DEBUG%"=="" @echo off
|
@if "%DEBUG%"=="" @echo off
|
||||||
@rem ##########################################################################
|
@rem ##########################################################################
|
||||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
|||||||
%JAVA_EXE% -version >NUL 2>&1
|
%JAVA_EXE% -version >NUL 2>&1
|
||||||
if %ERRORLEVEL% equ 0 goto execute
|
if %ERRORLEVEL% equ 0 goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
@@ -57,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
|||||||
|
|
||||||
if exist "%JAVA_EXE%" goto execute
|
if exist "%JAVA_EXE%" goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,13 @@
|
|||||||
plugins {
|
plugins {
|
||||||
id("com.gradle.enterprise") version "3.16.2"
|
id("com.gradle.develocity") version "3.17.6"
|
||||||
id("com.gradle.common-custom-user-data-gradle-plugin") version "1.12.1"
|
id("com.gradle.common-custom-user-data-gradle-plugin") version "2.0.1"
|
||||||
}
|
}
|
||||||
|
|
||||||
gradleEnterprise {
|
develocity {
|
||||||
buildScan {
|
buildScan {
|
||||||
termsOfServiceUrl = "https://gradle.com/terms-of-service"
|
termsOfUseUrl = "https://gradle.com/help/legal-terms-of-use"
|
||||||
termsOfServiceAgree = "yes"
|
termsOfUseAgree = "yes"
|
||||||
publishAlways()
|
uploadInBackground = false
|
||||||
isUploadInBackground = false
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,11 @@
|
|||||||
plugins {
|
plugins {
|
||||||
id "com.gradle.build-scan" version "3.16.2"
|
id "com.gradle.develocity" version "3.17.6"
|
||||||
}
|
}
|
||||||
|
|
||||||
gradleEnterprise {
|
develocity {
|
||||||
buildScan {
|
buildScan {
|
||||||
termsOfServiceUrl = "https://gradle.com/terms-of-service"
|
termsOfUseUrl = "https://gradle.com/help/legal-terms-of-use"
|
||||||
termsOfServiceAgree = "yes"
|
termsOfUseAgree = "yes"
|
||||||
publishAlways()
|
|
||||||
uploadInBackground = false
|
uploadInBackground = false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,12 +1,11 @@
|
|||||||
plugins {
|
plugins {
|
||||||
id "com.gradle.enterprise" version "3.16.2"
|
id "com.gradle.develocity" version "3.17.6"
|
||||||
}
|
}
|
||||||
|
|
||||||
gradleEnterprise {
|
develocity {
|
||||||
buildScan {
|
buildScan {
|
||||||
termsOfServiceUrl = "https://gradle.com/terms-of-service"
|
termsOfUseUrl = "https://gradle.com/help/legal-terms-of-use"
|
||||||
termsOfServiceAgree = "yes"
|
termsOfUseAgree = "yes"
|
||||||
publishAlways()
|
|
||||||
uploadInBackground = false
|
uploadInBackground = false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
@@ -1,7 +1,7 @@
|
|||||||
distributionBase=GRADLE_USER_HOME
|
distributionBase=GRADLE_USER_HOME
|
||||||
distributionPath=wrapper/dists
|
distributionPath=wrapper/dists
|
||||||
distributionSha256Sum=9d926787066a081739e8200858338b4a69e837c3a821a33aca9db09dd4a41026
|
distributionSha256Sum=d725d707bfabd4dfdc958c624003b3c80accc03f7037b5122c4b1d0ef15cecab
|
||||||
distributionUrl=https\://services.gradle.org/distributions/gradle-8.5-bin.zip
|
distributionUrl=https\://services.gradle.org/distributions/gradle-8.9-bin.zip
|
||||||
networkTimeout=10000
|
networkTimeout=10000
|
||||||
validateDistributionUrl=true
|
validateDistributionUrl=true
|
||||||
zipStoreBase=GRADLE_USER_HOME
|
zipStoreBase=GRADLE_USER_HOME
|
||||||
|
|||||||
@@ -15,6 +15,8 @@
|
|||||||
# See the License for the specific language governing permissions and
|
# See the License for the specific language governing permissions and
|
||||||
# limitations under the License.
|
# limitations under the License.
|
||||||
#
|
#
|
||||||
|
# SPDX-License-Identifier: Apache-2.0
|
||||||
|
#
|
||||||
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#
|
#
|
||||||
@@ -55,7 +57,7 @@
|
|||||||
# Darwin, MinGW, and NonStop.
|
# Darwin, MinGW, and NonStop.
|
||||||
#
|
#
|
||||||
# (3) This script is generated from the Groovy template
|
# (3) This script is generated from the Groovy template
|
||||||
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
|
||||||
# within the Gradle project.
|
# within the Gradle project.
|
||||||
#
|
#
|
||||||
# You can find Gradle at https://github.com/gradle/gradle/.
|
# You can find Gradle at https://github.com/gradle/gradle/.
|
||||||
@@ -84,7 +86,8 @@ done
|
|||||||
# shellcheck disable=SC2034
|
# shellcheck disable=SC2034
|
||||||
APP_BASE_NAME=${0##*/}
|
APP_BASE_NAME=${0##*/}
|
||||||
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
|
||||||
APP_HOME=$( cd "${APP_HOME:-./}" > /dev/null && pwd -P ) || exit
|
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s
|
||||||
|
' "$PWD" ) || exit
|
||||||
|
|
||||||
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
# Use the maximum available, or set MAX_FD != -1 to use that value.
|
||||||
MAX_FD=maximum
|
MAX_FD=maximum
|
||||||
|
|||||||
@@ -13,6 +13,8 @@
|
|||||||
@rem See the License for the specific language governing permissions and
|
@rem See the License for the specific language governing permissions and
|
||||||
@rem limitations under the License.
|
@rem limitations under the License.
|
||||||
@rem
|
@rem
|
||||||
|
@rem SPDX-License-Identifier: Apache-2.0
|
||||||
|
@rem
|
||||||
|
|
||||||
@if "%DEBUG%"=="" @echo off
|
@if "%DEBUG%"=="" @echo off
|
||||||
@rem ##########################################################################
|
@rem ##########################################################################
|
||||||
@@ -43,11 +45,11 @@ set JAVA_EXE=java.exe
|
|||||||
%JAVA_EXE% -version >NUL 2>&1
|
%JAVA_EXE% -version >NUL 2>&1
|
||||||
if %ERRORLEVEL% equ 0 goto execute
|
if %ERRORLEVEL% equ 0 goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
|
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
@@ -57,11 +59,11 @@ set JAVA_EXE=%JAVA_HOME%/bin/java.exe
|
|||||||
|
|
||||||
if exist "%JAVA_EXE%" goto execute
|
if exist "%JAVA_EXE%" goto execute
|
||||||
|
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
|
echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2
|
||||||
echo.
|
echo. 1>&2
|
||||||
echo Please set the JAVA_HOME variable in your environment to match the
|
echo Please set the JAVA_HOME variable in your environment to match the 1>&2
|
||||||
echo location of your Java installation.
|
echo location of your Java installation. 1>&2
|
||||||
|
|
||||||
goto fail
|
goto fail
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,11 @@
|
|||||||
plugins {
|
plugins {
|
||||||
id "com.gradle.enterprise" version "3.16.2"
|
id "com.gradle.develocity" version "3.17.6"
|
||||||
}
|
}
|
||||||
|
|
||||||
gradleEnterprise {
|
develocity {
|
||||||
buildScan {
|
buildScan {
|
||||||
termsOfServiceUrl = "https://gradle.com/terms-of-service"
|
termsOfUseUrl = "https://gradle.com/help/legal-terms-of-use"
|
||||||
termsOfServiceAgree = "yes"
|
termsOfUseAgree = "yes"
|
||||||
publishAlways()
|
|
||||||
uploadInBackground = false
|
uploadInBackground = false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
36
.github/workflows/ci-check-and-unit-test.yml
vendored
Normal file
36
.github/workflows/ci-check-and-unit-test.yml
vendored
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
name: CI-check-and-unit-test
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- 'main'
|
||||||
|
- 'release/**'
|
||||||
|
paths-ignore:
|
||||||
|
- 'dist/**'
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
check-format-and-unit-test:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
cache-dependency-path: sources/package-lock.json
|
||||||
|
|
||||||
|
- name: Check formatting and compile
|
||||||
|
run: |
|
||||||
|
npm install
|
||||||
|
npm run check
|
||||||
|
npm run compile
|
||||||
|
working-directory: sources
|
||||||
|
- name: Run unit tests
|
||||||
|
run: |
|
||||||
|
npm test
|
||||||
|
working-directory: sources
|
||||||
40
.github/workflows/ci-check-no-dist-update.yml
vendored
Normal file
40
.github/workflows/ci-check-no-dist-update.yml
vendored
Normal file
@@ -0,0 +1,40 @@
|
|||||||
|
name: CI-check-no-dist-update
|
||||||
|
|
||||||
|
# Prohibit any change to 'dist/**' on a non-release branch
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- 'dist/**'
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
fail-on-dist-update:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Get changed files
|
||||||
|
id: changed-files
|
||||||
|
uses: tj-actions/changed-files@v44
|
||||||
|
with:
|
||||||
|
files: |
|
||||||
|
dist/**
|
||||||
|
|
||||||
|
- name: Print changes to dist directory
|
||||||
|
env:
|
||||||
|
ALL_CHANGED_FILES: ${{ steps.changed-files.outputs.all_changed_files }}
|
||||||
|
run: |
|
||||||
|
for file in ${ALL_CHANGED_FILES}; do
|
||||||
|
echo "$file was changed"
|
||||||
|
done
|
||||||
|
|
||||||
|
- run: |
|
||||||
|
echo "The 'dist' directory is automatically updated by the release process."
|
||||||
|
echo "It should not be updated manually in a non-release branch or a pull request."
|
||||||
|
exit 1
|
||||||
12
.github/workflows/ci-codeql.yml
vendored
12
.github/workflows/ci-codeql.yml
vendored
@@ -2,9 +2,17 @@ name: CI-codeql
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [ "main" ]
|
branches:
|
||||||
|
- 'main'
|
||||||
|
- 'release/**'
|
||||||
|
- 'dev/**' # Allow running Code QL on dev branches without a PR
|
||||||
|
paths-ignore:
|
||||||
|
- 'dist/**'
|
||||||
pull_request:
|
pull_request:
|
||||||
branches: [ "main" ]
|
branches:
|
||||||
|
- 'main'
|
||||||
|
paths-ignore:
|
||||||
|
- 'dist/**'
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '25 23 * * 2'
|
- cron: '25 23 * * 2'
|
||||||
|
|
||||||
|
|||||||
20
.github/workflows/ci-dependency-review.yml
vendored
20
.github/workflows/ci-dependency-review.yml
vendored
@@ -1,20 +0,0 @@
|
|||||||
# Dependency Review Action
|
|
||||||
#
|
|
||||||
# This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.
|
|
||||||
#
|
|
||||||
# Source repository: https://github.com/actions/dependency-review-action
|
|
||||||
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
|
|
||||||
name: CI-dependency-review
|
|
||||||
on: [pull_request]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-review:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: 'Checkout Repository'
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: 'Dependency Review'
|
|
||||||
uses: actions/dependency-review-action@v4
|
|
||||||
107
.github/workflows/ci-full-check.yml
vendored
107
.github/workflows/ci-full-check.yml
vendored
@@ -1,107 +0,0 @@
|
|||||||
name: CI-full-check
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
pull_request:
|
|
||||||
types:
|
|
||||||
- assigned
|
|
||||||
- review_requested
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
- release/**
|
|
||||||
paths:
|
|
||||||
- '.github/**'
|
|
||||||
- 'dist/**'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
action-inputs:
|
|
||||||
uses: ./.github/workflows/integ-test-action-inputs.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
cache-cleanup:
|
|
||||||
uses: ./.github/workflows/integ-test-cache-cleanup.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
caching-config:
|
|
||||||
uses: ./.github/workflows/integ-test-caching-config.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
dependency-graph:
|
|
||||||
uses: ./.github/workflows/integ-test-dependency-graph.yml
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
dependency-graph-failures:
|
|
||||||
uses: ./.github/workflows/integ-test-dependency-graph-failures.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
execution-with-caching:
|
|
||||||
uses: ./.github/workflows/integ-test-execution-with-caching.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
execution:
|
|
||||||
uses: ./.github/workflows/integ-test-execution.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
develocity-injection:
|
|
||||||
uses: ./.github/workflows/integ-test-inject-develocity.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
secrets:
|
|
||||||
DEVELOCITY_ACCESS_KEY: ${{ secrets.GE_SOLUTIONS_ACCESS_TOKEN }}
|
|
||||||
|
|
||||||
provision-gradle-versions:
|
|
||||||
uses: ./.github/workflows/integ-test-provision-gradle-versions.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
restore-configuration-cache:
|
|
||||||
uses: ./.github/workflows/integ-test-restore-configuration-cache.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
secrets:
|
|
||||||
GRADLE_ENCRYPTION_KEY: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
|
||||||
|
|
||||||
restore-custom-gradle-home:
|
|
||||||
uses: ./.github/workflows/integ-test-restore-custom-gradle-home.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
restore-containerized-gradle-home:
|
|
||||||
uses: ./.github/workflows/integ-test-restore-containerized-gradle-home.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
restore-gradle-home:
|
|
||||||
uses: ./.github/workflows/integ-test-restore-gradle-home.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
restore-java-toolchain:
|
|
||||||
uses: ./.github/workflows/integ-test-restore-java-toolchain.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
sample-kotlin-dsl:
|
|
||||||
uses: ./.github/workflows/integ-test-sample-kotlin-dsl.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
sample-gradle-plugin:
|
|
||||||
uses: ./.github/workflows/integ-test-sample-gradle-plugin.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
|
|
||||||
toolchain-detection:
|
|
||||||
uses: ./.github/workflows/integ-test-detect-java-toolchains.yml
|
|
||||||
with:
|
|
||||||
cache-key-prefix: ${{github.run_number}}-
|
|
||||||
8
.github/workflows/ci-init-script-check.yml
vendored
8
.github/workflows/ci-init-script-check.yml
vendored
@@ -2,6 +2,12 @@ name: CI-init-script-check
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
branches:
|
||||||
|
- 'main'
|
||||||
|
- 'release/**'
|
||||||
|
paths-ignore:
|
||||||
|
- 'dist/**'
|
||||||
|
pull_request:
|
||||||
paths:
|
paths:
|
||||||
- '.github/workflows/ci-init-script-check.yml'
|
- '.github/workflows/ci-init-script-check.yml'
|
||||||
- 'sources/src/resources/init-scripts/**'
|
- 'sources/src/resources/init-scripts/**'
|
||||||
@@ -18,7 +24,7 @@ jobs:
|
|||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: temurin
|
distribution: temurin
|
||||||
java-version: 8
|
java-version: 11
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: gradle/actions/setup-gradle@v3 # Use a released version to avoid breakages
|
uses: gradle/actions/setup-gradle@v3 # Use a released version to avoid breakages
|
||||||
- name: Run integration tests
|
- name: Run integration tests
|
||||||
|
|||||||
202
.github/workflows/ci-integ-test.yml
vendored
Normal file
202
.github/workflows/ci-integ-test.yml
vendored
Normal file
@@ -0,0 +1,202 @@
|
|||||||
|
name: CI-integ-test
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- 'main'
|
||||||
|
- 'release/**'
|
||||||
|
- 'dev/**' # Allow running tests on dev branches without a PR
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: integ-tests-${{ github.ref }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
determine-suite:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
outputs:
|
||||||
|
runner-os: ${{ steps.determine-suite.outputs.suite == 'quick' && '["ubuntu-latest"]' || '["ubuntu-latest", "windows-latest", "macos-latest"]' }}
|
||||||
|
cache-key-prefix: '0' # TODO DAZ Try this again ${{ steps.determine-suite.outputs.suite == 'quick' && '0' || github.run_number }}
|
||||||
|
suite: ${{ steps.determine-suite.outputs.suite }}
|
||||||
|
steps:
|
||||||
|
- name: Determine suite to run
|
||||||
|
id: determine-suite
|
||||||
|
run: |
|
||||||
|
# Always run quick suite if we are not in the core `gradle/actions` repository
|
||||||
|
# This reduces the load for developers working on 'main' on forks
|
||||||
|
if [ "${{ github.repository }}" != "gradle/actions" ]; then
|
||||||
|
echo "Not in core repository: suite=quick"
|
||||||
|
echo "suite=quick" >> "$GITHUB_OUTPUT"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Run full suite for push trigger with "[bot] Update dist directory" commit message
|
||||||
|
if [ "${{ github.event.head_commit.message }}" == "[bot] Update dist directory" ]; then
|
||||||
|
echo "Bot commit to main branch: suite=full"
|
||||||
|
echo "suite=full" >> "$GITHUB_OUTPUT"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Run quick suite for everything else
|
||||||
|
echo "Everything else: suite=quick"
|
||||||
|
echo "suite=quick" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
build-distribution:
|
||||||
|
needs: [determine-suite]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Build and upload distribution
|
||||||
|
if: ${{ needs.determine-suite.outputs.suite != 'full' }}
|
||||||
|
uses: ./.github/actions/build-dist
|
||||||
|
|
||||||
|
build-scan-publish:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-build-scan-publish.yml
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
cache-cleanup:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-cache-cleanup.yml
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.suite}}-${{github.run_number}}-' # Requires a fresh cache entry each run
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
caching-config:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-caching-config.yml
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
dependency-graph:
|
||||||
|
if: ${{ ! github.event.pull_request.head.repo.fork }}
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-dependency-graph.yml
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
dependency-submission:
|
||||||
|
if: ${{ ! github.event.pull_request.head.repo.fork }}
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-dependency-submission.yml
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
dependency-submission-failures:
|
||||||
|
if: ${{ ! github.event.pull_request.head.repo.fork }}
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-dependency-submission-failures.yml
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
with:
|
||||||
|
runner-os: '${{ needs.determine-suite.outputs.runner-os }}'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
develocity-injection:
|
||||||
|
if: ${{ ! github.event.pull_request.head.repo.fork }}
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-inject-develocity.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
secrets:
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DV_SOLUTIONS_ACCESS_KEY }}
|
||||||
|
|
||||||
|
provision-gradle-versions:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-provision-gradle-versions.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
restore-configuration-cache:
|
||||||
|
if: ${{ ! github.event.pull_request.head.repo.fork }}
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-restore-configuration-cache.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
secrets:
|
||||||
|
GRADLE_ENCRYPTION_KEY: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
||||||
|
|
||||||
|
restore-containerized-gradle-home:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-restore-containerized-gradle-home.yml
|
||||||
|
with:
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
restore-custom-gradle-home:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-restore-custom-gradle-home.yml
|
||||||
|
with:
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
restore-gradle-home:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-restore-gradle-home.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
restore-java-toolchain:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-restore-java-toolchain.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
sample-kotlin-dsl:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-sample-kotlin-dsl.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
sample-gradle-plugin:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-sample-gradle-plugin.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
toolchain-detection:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-detect-java-toolchains.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
cache-key-prefix: '${{ needs.determine-suite.outputs.cache-key-prefix }}-'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
|
|
||||||
|
wrapper-validation:
|
||||||
|
needs: [determine-suite, build-distribution]
|
||||||
|
uses: ./.github/workflows/integ-test-wrapper-validation.yml
|
||||||
|
with:
|
||||||
|
runner-os: '["ubuntu-latest"]'
|
||||||
|
skip-dist: ${{ needs.determine-suite.outputs.suite == 'full' }}
|
||||||
156
.github/workflows/ci-quick-check.yml
vendored
156
.github/workflows/ci-quick-check.yml
vendored
@@ -1,156 +0,0 @@
|
|||||||
name: CI-quick-check
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
push:
|
|
||||||
branches-ignore:
|
|
||||||
- main
|
|
||||||
- release/**
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build-distribution:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Build and upload distribution
|
|
||||||
uses: ./.github/actions/build-dist
|
|
||||||
|
|
||||||
run-unit-tests:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Configure Gradle as default for unit test
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: 8.5
|
|
||||||
- name: Run tests
|
|
||||||
run: |
|
|
||||||
npm install
|
|
||||||
npm run all
|
|
||||||
working-directory: sources
|
|
||||||
|
|
||||||
action-inputs:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-action-inputs.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
cache-cleanup:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-cache-cleanup.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
cache-key-prefix: ${{github.run_number}}- # Requires a fresh cache entry each run
|
|
||||||
|
|
||||||
caching-config:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-caching-config.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
dependency-graph:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-dependency-graph.yml
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
dependency-graph-failures:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-dependency-graph-failures.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
execution-with-caching:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-execution-with-caching.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
execution:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-execution.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
develocity-injection:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-inject-develocity.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
secrets:
|
|
||||||
DEVELOCITY_ACCESS_KEY: ${{ secrets.GE_SOLUTIONS_ACCESS_TOKEN }}
|
|
||||||
|
|
||||||
provision-gradle-versions:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-provision-gradle-versions.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
restore-configuration-cache:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-restore-configuration-cache.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
secrets:
|
|
||||||
GRADLE_ENCRYPTION_KEY: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
|
||||||
|
|
||||||
restore-containerized-gradle-home:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-restore-containerized-gradle-home.yml
|
|
||||||
with:
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
restore-custom-gradle-home:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-restore-custom-gradle-home.yml
|
|
||||||
with:
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
restore-gradle-home:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-restore-gradle-home.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
restore-java-toolchain:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-restore-java-toolchain.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
sample-kotlin-dsl:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-sample-kotlin-dsl.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
sample-gradle-plugin:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-sample-gradle-plugin.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
|
|
||||||
toolchain-detection:
|
|
||||||
needs: build-distribution
|
|
||||||
uses: ./.github/workflows/integ-test-detect-java-toolchains.yml
|
|
||||||
with:
|
|
||||||
runner-os: '["ubuntu-latest"]'
|
|
||||||
download-dist: true
|
|
||||||
52
.github/workflows/ci-update-dist.yml
vendored
Normal file
52
.github/workflows/ci-update-dist.yml
vendored
Normal file
@@ -0,0 +1,52 @@
|
|||||||
|
name: CI-update-dist
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- 'main'
|
||||||
|
- 'release/**'
|
||||||
|
paths-ignore:
|
||||||
|
- 'dist/**'
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
update-dist:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
token: ${{ secrets.BOT_GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
- name: Set up Node.js
|
||||||
|
uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
cache-dependency-path: sources/package-lock.json
|
||||||
|
|
||||||
|
- name: Build distribution
|
||||||
|
run: |
|
||||||
|
npm clean-install
|
||||||
|
npm run check
|
||||||
|
npm run compile
|
||||||
|
working-directory: sources
|
||||||
|
|
||||||
|
- name: Copy the generated sources/dist directory to the top-level dist
|
||||||
|
run: |
|
||||||
|
cp -r sources/dist .
|
||||||
|
|
||||||
|
# Commit and push changes; has no effect if the files did not change
|
||||||
|
# Important: The push event will not trigger any other workflows, see
|
||||||
|
# https://github.com/stefanzweifel/git-auto-commit-action?tab=readme-ov-file#commits-made-by-this-action-do-not-trigger-new-workflow-runs
|
||||||
|
- name: Commit & push changes
|
||||||
|
# Only run for the Gradle repository; otherwise when users create pull requests from their `main` branch
|
||||||
|
# it would erroneously update `dist` on their branch (and the pull request)
|
||||||
|
if: github.repository == 'gradle/actions'
|
||||||
|
uses: stefanzweifel/git-auto-commit-action@v5
|
||||||
|
with:
|
||||||
|
commit_message: '[bot] Update dist directory'
|
||||||
|
file_pattern: dist
|
||||||
45
.github/workflows/ci-verify-outputs.yml
vendored
45
.github/workflows/ci-verify-outputs.yml
vendored
@@ -1,45 +0,0 @@
|
|||||||
name: CI-verify-outputs
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
types:
|
|
||||||
- assigned
|
|
||||||
- review_requested
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
- release/**
|
|
||||||
- dependabot/**
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
check:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 20
|
|
||||||
- name: Build
|
|
||||||
run: |
|
|
||||||
npm -v
|
|
||||||
node -v
|
|
||||||
npm install
|
|
||||||
npm run build
|
|
||||||
working-directory: sources
|
|
||||||
|
|
||||||
- name: Compare the expected and actual dist/ directories
|
|
||||||
run: |
|
|
||||||
if [ "$(git diff --ignore-space-at-eol dist/ | wc -l)" -gt "0" ]; then
|
|
||||||
echo "Detected uncommitted changes after build. See status below:"
|
|
||||||
git diff
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
id: diff
|
|
||||||
|
|
||||||
# If index.js was different than expected, upload the expected version as an artifact
|
|
||||||
- uses: actions/upload-artifact@v4
|
|
||||||
if: ${{ failure() && steps.diff.conclusion == 'failure' }}
|
|
||||||
with:
|
|
||||||
name: dist
|
|
||||||
path: dist/
|
|
||||||
43
.github/workflows/demo-failure-cases.yml
vendored
43
.github/workflows/demo-failure-cases.yml
vendored
@@ -1,43 +0,0 @@
|
|||||||
name: demo-failure-cases
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
|
|
||||||
failing-build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Test build failure
|
|
||||||
uses: ./setup-gradle
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/kotlin-dsl
|
|
||||||
arguments: not-a-valid-task
|
|
||||||
|
|
||||||
wrapper-missing:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Test wrapper missing
|
|
||||||
uses: ./setup-gradle
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper
|
|
||||||
arguments: help
|
|
||||||
|
|
||||||
bad-configuration:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Test bad config value
|
|
||||||
uses: ./setup-gradle
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper
|
|
||||||
arguments: help
|
|
||||||
cache-disabled: yes
|
|
||||||
50
.github/workflows/demo-job-summary.yml
vendored
50
.github/workflows/demo-job-summary.yml
vendored
@@ -2,22 +2,30 @@ name: Demo Job Summary, for Gradle builds
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
push:
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
many-gradle-builds:
|
build-distribution:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Build distribution
|
- name: Build and upload distribution
|
||||||
shell: bash
|
uses: ./.github/actions/build-dist
|
||||||
run: |
|
|
||||||
npm install
|
many-gradle-builds:
|
||||||
npm run build
|
needs: build-distribution
|
||||||
working-directory: sources
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false
|
||||||
|
cache-cleanup: 'on-success'
|
||||||
- name: Build kotlin-dsl project
|
- name: Build kotlin-dsl project
|
||||||
working-directory: .github/workflow-samples/kotlin-dsl
|
working-directory: .github/workflow-samples/kotlin-dsl
|
||||||
run: ./gradlew assemble
|
run: ./gradlew assemble
|
||||||
@@ -35,22 +43,26 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
./gradlew tasks --no-daemon
|
./gradlew tasks --no-daemon
|
||||||
./gradlew help check
|
./gradlew help check
|
||||||
|
./gradlew wrapper --gradle-version 8.7 --gradle-distribution-sha256-sum 544c35d6bd849ae8a5ed0bcea39ba677dc40f49df7d1835561582da2009b961d
|
||||||
- name: Fail groovy-dsl project
|
- name: Fail groovy-dsl project
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
continue-on-error: true
|
continue-on-error: true
|
||||||
run: ./gradlew not-a-real-task
|
run: ./gradlew not-a-real-task
|
||||||
|
- name: Dependency submission
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
|
||||||
successful-builds-with-no-summary:
|
successful-builds-with-no-summary:
|
||||||
|
needs: build-distribution
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Build distribution
|
- name: Initialize integ-test
|
||||||
shell: bash
|
uses: ./.github/actions/init-integ-test
|
||||||
run: |
|
|
||||||
npm install
|
|
||||||
npm run build
|
|
||||||
working-directory: sources
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -63,16 +75,14 @@ jobs:
|
|||||||
run: ./gradlew assemble check --no-scan
|
run: ./gradlew assemble check --no-scan
|
||||||
|
|
||||||
pre-existing-gradle-home:
|
pre-existing-gradle-home:
|
||||||
|
needs: build-distribution
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Build distribution
|
- name: Initialize integ-test
|
||||||
shell: bash
|
uses: ./.github/actions/init-integ-test
|
||||||
run: |
|
|
||||||
npm install
|
|
||||||
npm run build
|
|
||||||
working-directory: sources
|
|
||||||
- name: Pre-create Gradle User Home
|
- name: Pre-create Gradle User Home
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
28
.github/workflows/demo-pr-build-scan-comment.yml
vendored
28
.github/workflows/demo-pr-build-scan-comment.yml
vendored
@@ -7,11 +7,23 @@ permissions:
|
|||||||
pull-requests: write
|
pull-requests: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
successful-build-with-always-comment:
|
build-distribution:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout project sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
- name: Build and upload distribution
|
||||||
|
uses: ./.github/actions/build-dist
|
||||||
|
|
||||||
|
successful-build-with-always-comment:
|
||||||
|
needs: build-distribution
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -22,10 +34,14 @@ jobs:
|
|||||||
run: ./gradlew build --scan
|
run: ./gradlew build --scan
|
||||||
|
|
||||||
successful-build-with-comment-on-failure:
|
successful-build-with-comment-on-failure:
|
||||||
|
needs: build-distribution
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout project sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -36,10 +52,14 @@ jobs:
|
|||||||
run: ./gradlew build --scan
|
run: ./gradlew build --scan
|
||||||
|
|
||||||
failing-build-with-comment-on-failure:
|
failing-build-with-comment-on-failure:
|
||||||
|
needs: build-distribution
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout project sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
22
.github/workflows/dependency-submission-save.yml
vendored
22
.github/workflows/dependency-submission-save.yml
vendored
@@ -1,22 +0,0 @@
|
|||||||
name: Test dependency-submission save
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
push:
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission-save:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and save dependency graph
|
|
||||||
uses: ./dependency-submission
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
dependency-graph: generate-and-upload
|
|
||||||
env:
|
|
||||||
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
|
||||||
@@ -1,20 +0,0 @@
|
|||||||
name: Test dependency-submission submit
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_run:
|
|
||||||
workflows: ['Test dependency-submission save']
|
|
||||||
types: [completed]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission-submit:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download and submit dependency graph
|
|
||||||
uses: ./dependency-submission
|
|
||||||
with:
|
|
||||||
dependency-graph: download-and-submit
|
|
||||||
61
.github/workflows/dependency-submission.yml
vendored
61
.github/workflows/dependency-submission.yml
vendored
@@ -1,61 +0,0 @@
|
|||||||
name: Test dependency-submission
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
push:
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
test-dependency-submission:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependencies
|
|
||||||
uses: ./dependency-submission
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
env:
|
|
||||||
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
|
||||||
|
|
||||||
test-gradle-versions:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
gradle: [8.0.2, 7.6.4, 7.1.1, 6.9.4, 6.0.1, 5.6.4, 5.2.1]
|
|
||||||
include:
|
|
||||||
- gradle: 5.6.4
|
|
||||||
build-root-suffix: -gradle-5
|
|
||||||
- gradle: 5.2.1
|
|
||||||
build-root-suffix: -gradle-5
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependencies
|
|
||||||
uses: ./dependency-submission
|
|
||||||
with:
|
|
||||||
gradle-version: ${{ matrix.gradle }}
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper${{ matrix.build-root-suffix }}
|
|
||||||
env:
|
|
||||||
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
|
||||||
|
|
||||||
test-after-setup-gradle:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle
|
|
||||||
uses: ./setup-gradle
|
|
||||||
- name: Generate and submit dependencies
|
|
||||||
id: dependency-submission
|
|
||||||
uses: ./dependency-submission
|
|
||||||
continue-on-error: true
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
- name: Assert step failure
|
|
||||||
if: steps.dependency-submission.outcome != 'failure'
|
|
||||||
run: |
|
|
||||||
echo "Dependency submission step should fail after setup-gradle"
|
|
||||||
exit 1
|
|
||||||
40
.github/workflows/integ-test-action-inputs.yml
vendored
40
.github/workflows/integ-test-action-inputs.yml
vendored
@@ -1,40 +0,0 @@
|
|||||||
name: Test action inputs
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
cache-key-prefix:
|
|
||||||
type: string
|
|
||||||
runner-os:
|
|
||||||
type: string
|
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
|
||||||
download-dist:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
env:
|
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: action-inputs-${{ inputs.cache-key-prefix }}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
action-inputs:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Invoke with multi-line arguments
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
arguments: |
|
|
||||||
--configuration-cache
|
|
||||||
--build-cache
|
|
||||||
-DsystemProperty=FOO
|
|
||||||
-PgradleProperty=BAR
|
|
||||||
test
|
|
||||||
jar
|
|
||||||
57
.github/workflows/integ-test-build-scan-publish.yml
vendored
Normal file
57
.github/workflows/integ-test-build-scan-publish.yml
vendored
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
name: Test develocity injection
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
cache-key-prefix:
|
||||||
|
type: string
|
||||||
|
runner-os:
|
||||||
|
type: string
|
||||||
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
|
skip-dist:
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: build-scan-publish-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-scan-publish:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
gradle: [current, 7.6.2, 6.9.4, 5.6.4]
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 11
|
||||||
|
- name: Setup Gradle
|
||||||
|
id: setup-gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
gradle-version: ${{ matrix.gradle }}
|
||||||
|
build-scan-publish: true
|
||||||
|
build-scan-terms-of-use-url: "https://gradle.com/terms-of-service"
|
||||||
|
build-scan-terms-of-use-agree: "yes"
|
||||||
|
- name: Run Gradle build
|
||||||
|
id: gradle
|
||||||
|
working-directory: .github/workflow-samples/no-ge
|
||||||
|
run: gradle help
|
||||||
|
- name: Check Build Scan url
|
||||||
|
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
||||||
|
uses: actions/github-script@v7
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
core.setFailed('No Build Scan detected')
|
||||||
|
|
||||||
43
.github/workflows/integ-test-cache-cleanup.yml
vendored
43
.github/workflows/integ-test-cache-cleanup.yml
vendored
@@ -8,79 +8,92 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: integ-test-cache-cleanup-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: cache-cleanup-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
full-build:
|
full-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
- name: Build with 3.1
|
- name: Build with 3.1
|
||||||
working-directory: sources/test/jest/resources/cache-cleanup
|
working-directory: sources/test/jest/resources/cache-cleanup
|
||||||
run: gradle --no-daemon --build-cache -Dcommons_math3_version="3.1" build
|
run: ./gradlew --no-daemon --build-cache -Dcommons_math3_version="3.1" build
|
||||||
|
|
||||||
# Second build will use the cache from the first build, but cleanup should remove unused artifacts
|
# Second build will use the cache from the first build, but cleanup should remove unused artifacts
|
||||||
assemble-build:
|
assemble-build:
|
||||||
needs: full-build
|
needs: full-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: false
|
cache-read-only: false
|
||||||
gradle-home-cache-cleanup: true
|
cache-cleanup: 'on-success'
|
||||||
- name: Build with 3.1.1
|
- name: Build with 3.1.1
|
||||||
working-directory: sources/test/jest/resources/cache-cleanup
|
working-directory: sources/test/jest/resources/cache-cleanup
|
||||||
run: gradle --no-daemon --build-cache -Dcommons_math3_version="3.1.1" build
|
run: ./gradlew --no-daemon --build-cache -Dcommons_math3_version="3.1.1" build
|
||||||
|
|
||||||
check-clean-cache:
|
check-clean-cache:
|
||||||
needs: assemble-build
|
needs: assemble-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: true
|
cache-read-only: true
|
||||||
- name: Report Gradle User Home
|
- name: Report Gradle User Home
|
||||||
run: du -hc ~/.gradle/caches/modules-2
|
shell: bash
|
||||||
|
run: |
|
||||||
|
du -hc $GRADLE_USER_HOME/caches/modules-2
|
||||||
|
du -hc $GRADLE_USER_HOME/wrapper/dists
|
||||||
- name: Verify cleaned cache
|
- name: Verify cleaned cache
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
if [ ! -e ~/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-math3/3.1.1 ]; then
|
if [ ! -e $GRADLE_USER_HOME/caches/modules-2/files-2.1/org.apache.commons/commons-math3/3.1.1 ]; then
|
||||||
echo "::error ::Should find commons-math3 3.1.1 in cache"
|
echo "::error ::Should find commons-math3 3.1.1 in cache"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
if [ -e ~/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-math3/3.1 ]; then
|
if [ -e $GRADLE_USER_HOME/caches/modules-2/files-2.1/org.apache.commons/commons-math3/3.1 ]; then
|
||||||
echo "::error ::Should NOT find commons-math3 3.1 in cache"
|
echo "::error ::Should NOT find commons-math3 3.1 in cache"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
if [ ! -e $GRADLE_USER_HOME/wrapper/dists/gradle-8.0.2-bin ]; then
|
||||||
|
echo "::error ::Should find gradle-8.0.2 in wrapper/dists"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|||||||
61
.github/workflows/integ-test-caching-config.yml
vendored
61
.github/workflows/integ-test-caching-config.yml
vendored
@@ -8,33 +8,35 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: action-inputs-caching-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: caching-config-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
# Add "enterprise" to main cache entry but omit "notifications"
|
# Add "application" to main cache entry but omit "notifications"
|
||||||
gradle-home-cache-includes: |
|
gradle-home-cache-includes: |
|
||||||
caches
|
caches
|
||||||
enterprise
|
application
|
||||||
# Exclude build-cache from main cache entry
|
# Exclude build-cache from main cache entry
|
||||||
gradle-home-cache-excludes: |
|
gradle-home-cache-excludes: |
|
||||||
caches/build-cache-*
|
caches/build-cache-*
|
||||||
@@ -47,21 +49,23 @@ jobs:
|
|||||||
verify-build:
|
verify-build:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
# Use the same configuration as used in the seed build
|
# Use the same configuration as used in the seed build
|
||||||
gradle-home-cache-includes: |
|
gradle-home-cache-includes: |
|
||||||
caches
|
caches
|
||||||
enterprise
|
application
|
||||||
gradle-home-cache-excludes: |
|
gradle-home-cache-excludes: |
|
||||||
caches/build-cache-*
|
caches/build-cache-*
|
||||||
caches/*/executionHistory
|
caches/*/executionHistory
|
||||||
@@ -73,22 +77,24 @@ jobs:
|
|||||||
# Test that build scans are captured when caching is explicitly disabled
|
# Test that build scans are captured when caching is explicitly disabled
|
||||||
cache-disabled:
|
cache-disabled:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-disabled: true
|
cache-disabled: true
|
||||||
- name: Run Gradle build
|
- name: Build using Gradle wrapper
|
||||||
id: gradle
|
id: gradle
|
||||||
working-directory: .github/workflow-samples/no-wrapper${{ matrix.build-root-suffix }}
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
run: gradle help "-DgradleVersionCheck=${{matrix.gradle}}"
|
run: ./gradlew help
|
||||||
- name: Check Build Scan url is captured
|
- name: Check Build Scan url is captured
|
||||||
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v7
|
||||||
@@ -98,20 +104,21 @@ jobs:
|
|||||||
|
|
||||||
# Test that build scans are captured when caching is disabled because Gradle User Home already exists
|
# Test that build scans are captured when caching is disabled because Gradle User Home already exists
|
||||||
cache-disabled-pre-existing-gradle-home:
|
cache-disabled-pre-existing-gradle-home:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest # This test only runs on Ubuntu
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Create dummy Gradle User Home
|
- name: Create dummy Gradle User Home
|
||||||
run: mkdir -p ~/.gradle/caches
|
run: mkdir -p ~/.gradle/caches
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
- name: Run Gradle build
|
- name: Build using Gradle wrapper
|
||||||
id: gradle
|
id: gradle
|
||||||
working-directory: .github/workflow-samples/no-wrapper${{ matrix.build-root-suffix }}
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
run: gradle help "-DgradleVersionCheck=${{matrix.gradle}}"
|
run: ./gradlew help
|
||||||
- name: Check Build Scan url is captured
|
- name: Check Build Scan url is captured
|
||||||
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v7
|
||||||
@@ -124,14 +131,16 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: ${{ inputs.cache-key-prefix }}-write-only-
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: ${{ inputs.cache-key-prefix }}-write-only-
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -145,14 +154,16 @@ jobs:
|
|||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: ${{ inputs.cache-key-prefix }}-write-only-
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: ${{ inputs.cache-key-prefix }}-write-only-
|
||||||
needs: seed-build-write-only
|
needs: seed-build-write-only
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -1,128 +0,0 @@
|
|||||||
name: Test dependency graph
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
cache-key-prefix:
|
|
||||||
type: string
|
|
||||||
runner-os:
|
|
||||||
type: string
|
|
||||||
default: '["ubuntu-latest"]'
|
|
||||||
download-dist:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
env:
|
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: dependency-graph-${{ inputs.cache-key-prefix }}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
failing-build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
dependency-graph: generate
|
|
||||||
dependency-graph-continue-on-failure: true
|
|
||||||
- name: Run build that will fail
|
|
||||||
id: gradle-build
|
|
||||||
continue-on-error: true
|
|
||||||
run: ./gradlew build fail
|
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
- name: Check no dependency graph is generated
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
if [ ! -z "$(ls -A dependency-graph-reports)" ]; then
|
|
||||||
echo "Expected no dependency graph files to be generated"
|
|
||||||
ls -l dependency-graph-reports
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
unsupported-gradle-version-warning:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: 7.0.1
|
|
||||||
dependency-graph: generate
|
|
||||||
dependency-graph-continue-on-failure: true
|
|
||||||
- name: Run with unsupported Gradle version
|
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
run: |
|
|
||||||
if gradle help | grep -q 'warning::Dependency Graph is not supported for Gradle 7.0.1. No dependency snapshot will be generated.';
|
|
||||||
then
|
|
||||||
echo "Got the expected warning"
|
|
||||||
else
|
|
||||||
echo "Did not get the expected warning"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
unsupported-gradle-version-failure:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: 7.0.1
|
|
||||||
dependency-graph: generate
|
|
||||||
dependency-graph-continue-on-failure: false
|
|
||||||
- name: Run with unsupported Gradle version
|
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
run: |
|
|
||||||
if gradle help; then
|
|
||||||
echo "Expected build to fail with Gradle 7.0.1"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
insufficient-permissions-warning:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-submit
|
|
||||||
dependency-graph-continue-on-failure: true
|
|
||||||
- name: Run with insufficient permissions
|
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
run: ./gradlew help
|
|
||||||
# This test is primarily for demonstration: it's unclear how to check for warnings emitted in the post-action
|
|
||||||
|
|
||||||
SHOULD_FAIL-insufficient-permissions-failure:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
continue-on-error: true
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-submit
|
|
||||||
dependency-graph-continue-on-failure: false
|
|
||||||
- name: Run with insufficient permissions
|
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
run: ./gradlew help
|
|
||||||
# This test is primarily for demonstration: it's unclear how to check for a failure in the post-action
|
|
||||||
@@ -8,7 +8,7 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
@@ -16,20 +16,23 @@ permissions:
|
|||||||
contents: write
|
contents: write
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: dependency-graph-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: dependency-graph-${{ inputs.cache-key-prefix }}
|
||||||
|
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
groovy-generate:
|
groovy-upload:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
- name: Setup Gradle for dependency-graph generate
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -38,16 +41,34 @@ jobs:
|
|||||||
run: ./gradlew build
|
run: ./gradlew build
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
|
||||||
kotlin-generate:
|
groovy-submit:
|
||||||
|
needs: [groovy-upload]
|
||||||
|
runs-on: "ubuntu-latest"
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Submit dependency graphs
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
dependency-graph: download-and-submit
|
||||||
|
env:
|
||||||
|
DEPENDENCY_GRAPH_DOWNLOAD_ARTIFACT_NAME: groovy-upload
|
||||||
|
|
||||||
|
kotlin-generate-and-submit:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
- name: Setup Gradle for dependency-graph generate
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -55,30 +76,19 @@ jobs:
|
|||||||
- name: Run gradle build
|
- name: Run gradle build
|
||||||
run: ./gradlew build
|
run: ./gradlew build
|
||||||
working-directory: .github/workflow-samples/kotlin-dsl
|
working-directory: .github/workflow-samples/kotlin-dsl
|
||||||
|
|
||||||
submit:
|
|
||||||
needs: [groovy-generate]
|
|
||||||
runs-on: "ubuntu-latest"
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Submit dependency graphs
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
dependency-graph: download-and-submit
|
|
||||||
|
|
||||||
multiple-builds:
|
multiple-builds:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
- name: Setup Gradle for dependency-graph generate
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -113,12 +123,13 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
config-cache:
|
config-cache:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest # Test is not compatible with Windows
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle for dependency-graph generate
|
- name: Setup Gradle for dependency-graph generate
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
99
.github/workflows/integ-test-dependency-submission-failures.yml
vendored
Normal file
99
.github/workflows/integ-test-dependency-submission-failures.yml
vendored
Normal file
@@ -0,0 +1,99 @@
|
|||||||
|
name: Test dependency submission failures
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
cache-key-prefix:
|
||||||
|
type: string
|
||||||
|
runner-os:
|
||||||
|
type: string
|
||||||
|
default: '["ubuntu-latest"]'
|
||||||
|
skip-dist:
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: dependency-submission-failures-${{ inputs.cache-key-prefix }}
|
||||||
|
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
failing-build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Submit with failing build
|
||||||
|
id: gradle-build
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
additional-arguments: fail
|
||||||
|
continue-on-error: true
|
||||||
|
- name: Check step failed
|
||||||
|
if: steps.gradle-build.outcome != 'failure'
|
||||||
|
run: |
|
||||||
|
echo "Expected dependency submission step to fail"
|
||||||
|
exit 1
|
||||||
|
- name: Check no dependency graph is generated
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -z "$(ls -A dependency-graph-reports)" ]; then
|
||||||
|
echo "Expected no dependency graph files to be generated"
|
||||||
|
ls -l dependency-graph-reports
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
unsupported-gradle-version:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Submit with unsupported Gradle version
|
||||||
|
id: gradle-build
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
gradle-version: 7.0.1
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
continue-on-error: true
|
||||||
|
- name: Check step failed
|
||||||
|
if: steps.gradle-build.outcome != 'failure'
|
||||||
|
run: |
|
||||||
|
echo "Expected dependency submission step to fail"
|
||||||
|
exit 1
|
||||||
|
- name: Check no dependency graph is generated
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -z "$(ls -A dependency-graph-reports)" ]; then
|
||||||
|
echo "Expected no dependency graph files to be generated"
|
||||||
|
ls -l dependency-graph-reports
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
insufficient-permissions:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Submit with insufficient permissions
|
||||||
|
id: gradle-build
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
continue-on-error: true
|
||||||
|
- name: Check step failed
|
||||||
|
if: steps.gradle-build.outcome != 'failure'
|
||||||
|
run: |
|
||||||
|
echo "Expected dependency submission step to fail"
|
||||||
|
exit 1
|
||||||
373
.github/workflows/integ-test-dependency-submission.yml
vendored
Normal file
373
.github/workflows/integ-test-dependency-submission.yml
vendored
Normal file
@@ -0,0 +1,373 @@
|
|||||||
|
name: Test dependency submission
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
cache-key-prefix:
|
||||||
|
type: string
|
||||||
|
runner-os:
|
||||||
|
type: string
|
||||||
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
|
skip-dist:
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
env:
|
||||||
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: dependency-submission-${{ inputs.cache-key-prefix }}
|
||||||
|
GITHUB_DEPENDENCY_GRAPH_REF: 'refs/tags/v0.0.1' # Use a different ref to avoid updating the real dependency graph for the repository
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
groovy-generate-and-upload:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate dependency graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
cache-read-only: false
|
||||||
|
env:
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: groovy-dependency-submission
|
||||||
|
|
||||||
|
groovy-restore-cache:
|
||||||
|
needs: [groovy-generate-and-upload]
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Restore dependency graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
additional-arguments: --offline
|
||||||
|
env:
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: groovy-dependency-submission
|
||||||
|
|
||||||
|
groovy-download-and-submit:
|
||||||
|
needs: [groovy-generate-and-upload]
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Submit dependency graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: download-and-submit
|
||||||
|
env:
|
||||||
|
DEPENDENCY_GRAPH_DOWNLOAD_ARTIFACT_NAME: groovy-generate-and-upload-${{ matrix.os }}
|
||||||
|
|
||||||
|
kotlin-generate-and-submit:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/kotlin-dsl
|
||||||
|
|
||||||
|
multiple-builds:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- id: kotlin-dsl
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/kotlin-dsl
|
||||||
|
- id: groovy-dsl
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
- id: groovy-dsl-again
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
dependency-resolution-task: assemble
|
||||||
|
- name: Check generated dependency graphs
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "kotlin-dsl report file: ${{ steps.kotlin-dsl.outputs.dependency-graph-file }}"
|
||||||
|
echo "groovy-dsl report file: ${{ steps.groovy-dsl.outputs.dependency-graph-file }}"
|
||||||
|
echo "groovy-dsl-again report file: ${{ steps.groovy-dsl-again.outputs.dependency-graph-file }}"
|
||||||
|
ls -l dependency-graph-reports
|
||||||
|
if [ ! -e "${{ steps.kotlin-dsl.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find kotlin-dsl dependency graph file"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ ! -e "${{ steps.groovy-dsl.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find groovy-dsl dependency graph file"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ ! -e "${{ steps.groovy-dsl-again.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find groovy-dsl-again dependency graph file"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
multiple-builds-upload:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- id: kotlin-dsl
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
build-root-directory: .github/workflow-samples/kotlin-dsl
|
||||||
|
- id: groovy-dsl
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
|
||||||
|
config-cache:
|
||||||
|
runs-on: ubuntu-latest # Test is not compatible with Windows
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- id: config-cache-store
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
additional-arguments: --configuration-cache
|
||||||
|
- name: Check and delete generated dependency graph
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -e "${{ steps.config-cache-store.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find config-cache-store dependency graph files"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
rm ${{ steps.config-cache-store.outputs.dependency-graph-file }}*
|
||||||
|
- id: config-cache-reuse
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
additional-arguments: --configuration-cache
|
||||||
|
- name: Check no dependency graph is generated
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -z "$(ls -A dependency-graph-reports)" ]; then
|
||||||
|
echo "Expected no dependency graph files to be generated"
|
||||||
|
ls -l dependency-graph-reports
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
gradle-versions:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
gradle: [8.0.2, 7.6.4, 7.1.1, 6.9.4, 6.0.1, 5.6.4, 5.2.1]
|
||||||
|
include:
|
||||||
|
- gradle: 5.6.4
|
||||||
|
build-root-suffix: -gradle-5
|
||||||
|
- gradle: 5.2.1
|
||||||
|
build-root-suffix: -gradle-5
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate and submit dependencies
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
gradle-version: ${{ matrix.gradle }}
|
||||||
|
build-root-directory: .github/workflow-samples/no-wrapper${{ matrix.build-root-suffix }}
|
||||||
|
|
||||||
|
with-setup-gradle:
|
||||||
|
runs-on: ubuntu-latest # Test is not compatible with Windows
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
- name: Generate and submit dependencies
|
||||||
|
id: dependency-submission
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
- name: Check and delete generated dependency graph
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -e "${{ steps.dependency-submission.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find generated dependency graph files"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
rm ${{ steps.dependency-submission.outputs.dependency-graph-file }}*
|
||||||
|
- name: Run Gradle build
|
||||||
|
run: ./gradlew build
|
||||||
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
- name: Check no dependency graph is generated
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -z "$(ls -A dependency-graph-reports)" ]; then
|
||||||
|
echo "Expected no dependency graph files to be generated"
|
||||||
|
ls -l dependency-graph-reports
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
with-includes-and-excludes:
|
||||||
|
runs-on: ubuntu-latest # Test is not compatible with Windows
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate and submit dependencies
|
||||||
|
id: dependency-submission
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
dependency-graph-exclude-projects: excluded-project
|
||||||
|
dependency-graph-include-projects: included-project
|
||||||
|
dependency-graph-exclude-configurations: excluded-configuration
|
||||||
|
dependency-graph-include-configurations: included-configuration
|
||||||
|
- name: Check generated dependency graph and env vars
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ ! -e "${{ steps.dependency-submission.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find generated dependency graph file"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$DEPENDENCY_GRAPH_EXCLUDE_PROJECTS" != "excluded-project" ] ||
|
||||||
|
[ "$DEPENDENCY_GRAPH_INCLUDE_PROJECTS" != "included-project" ] ||
|
||||||
|
[ "$DEPENDENCY_GRAPH_EXCLUDE_CONFIGURATIONS" != "excluded-configuration" ] ||
|
||||||
|
[ "$DEPENDENCY_GRAPH_INCLUDE_CONFIGURATIONS" != "included-configuration" ]; then
|
||||||
|
echo "Did not set expected environment variables"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
custom-report-dir-submit:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate dependency graph
|
||||||
|
id: dependency-graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-submit
|
||||||
|
dependency-graph-report-dir: '${{ github.workspace }}/custom/report-dir'
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
- name: Check generated dependency graphs
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "report file: ${{ steps.dependency-graph.outputs.dependency-graph-file }}"
|
||||||
|
|
||||||
|
if [ ! -e "${{ steps.dependency-graph.outputs.dependency-graph-file }}" ]; then
|
||||||
|
echo "Did not find dependency graph file"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -z "$(ls -A "${{ github.workspace }}/custom/report-dir")" ]; then
|
||||||
|
echo "No dependency graph files found in custom directory"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
custom-report-dir-upload:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Generate and upload dependency graph
|
||||||
|
id: dependency-graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
dependency-graph-report-dir: '${{ github.workspace }}/custom/report-dir'
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
|
||||||
|
custom-report-dir-download-and-submit:
|
||||||
|
needs: custom-report-dir-upload
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Download and submit dependency graph
|
||||||
|
uses: ./dependency-submission
|
||||||
|
with:
|
||||||
|
dependency-graph: download-and-submit
|
||||||
|
dependency-graph-report-dir: '${{ github.workspace }}/custom/report-dir'
|
||||||
|
build-root-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
env:
|
||||||
|
DEPENDENCY_GRAPH_DOWNLOAD_ARTIFACT_NAME: custom-report-dir-upload # For testing, to avoid downloading artifacts from other worklfows
|
||||||
|
|
||||||
|
- name: Check downloaded dependency graph
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ -z "$(ls -A "${{ github.workspace }}/custom/report-dir")" ]; then
|
||||||
|
echo "No dependency graph files found in custom directory"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
@@ -8,12 +8,12 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: detect-java-toolchain-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: detect-java-toolchain-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
@@ -27,15 +27,16 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
- name: List detected toolchains
|
- name: List detected toolchains
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
run: |
|
run: |
|
||||||
gradle --info javaToolchains > output.txt
|
./gradlew --info javaToolchains > output.txt
|
||||||
cat output.txt
|
cat output.txt
|
||||||
- name: Verify detected toolchains
|
- name: Verify detected toolchains
|
||||||
shell: bash
|
shell: bash
|
||||||
@@ -56,25 +57,26 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java 20
|
- name: Setup Java 20
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'temurin'
|
distribution: 'temurin'
|
||||||
java-version: '20'
|
java-version: 20
|
||||||
- name: Setup Java 16
|
- name: Setup Java 16
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'temurin'
|
distribution: 'temurin'
|
||||||
java-version: '16'
|
java-version: 16
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
- name: List detected toolchains
|
- name: List detected toolchains
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
run: |
|
run: |
|
||||||
gradle --info javaToolchains > output.txt
|
./gradlew --info javaToolchains > output.txt
|
||||||
cat output.txt
|
cat output.txt
|
||||||
- name: Verify setup JDKs are detected
|
- name: Verify setup JDKs are detected
|
||||||
shell: bash
|
shell: bash
|
||||||
|
|||||||
@@ -1,56 +0,0 @@
|
|||||||
name: Test execution with caching
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
cache-key-prefix:
|
|
||||||
type: string
|
|
||||||
runner-os:
|
|
||||||
type: string
|
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
|
||||||
download-dist:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
env:
|
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: execution-with-caching-${{ inputs.cache-key-prefix }}
|
|
||||||
GRADLE_BUILD_ACTION_CACHE_DEBUG_ENABLED: true
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
seed-build:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Execute Gradle build
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
arguments: test
|
|
||||||
|
|
||||||
# Test that the gradle-user-home is restored
|
|
||||||
verify-build:
|
|
||||||
needs: seed-build
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Execute Gradle build
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
cache-read-only: true
|
|
||||||
build-root-directory: .github/workflow-samples/groovy-dsl
|
|
||||||
arguments: test --offline -DverifyCachedBuild=true
|
|
||||||
|
|
||||||
93
.github/workflows/integ-test-execution.yml
vendored
93
.github/workflows/integ-test-execution.yml
vendored
@@ -1,93 +0,0 @@
|
|||||||
name: Test execution
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
cache-key-prefix:
|
|
||||||
type: string
|
|
||||||
runner-os:
|
|
||||||
type: string
|
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
|
||||||
download-dist:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
env:
|
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: execution-${{ inputs.cache-key-prefix }}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
# Tests for executing with different Gradle versions.
|
|
||||||
# Each build verifies that it is executed with the expected Gradle version.
|
|
||||||
gradle-execution:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
|
||||||
include:
|
|
||||||
- os: windows-latest
|
|
||||||
script-suffix: '.bat'
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Test use defined Gradle version
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
|
||||||
gradle-version: 6.9
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper
|
|
||||||
arguments: help -DgradleVersionCheck=6.9
|
|
||||||
- name: Test use Gradle version alias
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: release-candidate
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper
|
|
||||||
arguments: help
|
|
||||||
- name: Test with non-executable wrapper
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: wrapper
|
|
||||||
build-root-directory: .github/workflow-samples/non-executable-wrapper
|
|
||||||
arguments: help
|
|
||||||
|
|
||||||
gradle-versions:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
gradle: [7.5.1, 6.9.2, 5.6.4, 4.10.3, 3.5.1]
|
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
|
||||||
include:
|
|
||||||
- gradle: 5.6.4
|
|
||||||
build-root-suffix: -gradle-5
|
|
||||||
- gradle: 4.10.3
|
|
||||||
build-root-suffix: -gradle-4
|
|
||||||
- gradle: 3.5.1
|
|
||||||
build-root-suffix: -gradle-4
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Java
|
|
||||||
uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
distribution: temurin
|
|
||||||
java-version: 8
|
|
||||||
- name: Run Gradle build
|
|
||||||
uses: ./setup-gradle
|
|
||||||
id: gradle
|
|
||||||
with:
|
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
|
||||||
gradle-version: ${{matrix.gradle}}
|
|
||||||
build-root-directory: .github/workflow-samples/no-wrapper${{ matrix.build-root-suffix }}
|
|
||||||
arguments: help -DgradleVersionCheck=${{matrix.gradle}}
|
|
||||||
- name: Check Build Scan url
|
|
||||||
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
|
||||||
uses: actions/github-script@v7
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
core.setFailed('No Build Scan detected')
|
|
||||||
|
|
||||||
|
|
||||||
185
.github/workflows/integ-test-inject-develocity.yml
vendored
185
.github/workflows/integ-test-inject-develocity.yml
vendored
@@ -8,7 +8,7 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
secrets:
|
secrets:
|
||||||
@@ -16,32 +16,41 @@ on:
|
|||||||
required: true
|
required: true
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: provision-gradle-versions-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: inject-develocity-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
inject-develocity:
|
inject-develocity:
|
||||||
env:
|
env:
|
||||||
DEVELOCITY_INJECTION_ENABLED: true
|
DEVELOCITY_INJECTION_ENABLED: true
|
||||||
DEVELOCITY_URL: https://ge.solutions-team.gradle.com
|
DEVELOCITY_URL: https://ge.solutions-team.gradle.com
|
||||||
DEVELOCITY_PLUGIN_VERSION: 3.16.2
|
DEVELOCITY_PLUGIN_VERSION: ${{ matrix.plugin-version }}
|
||||||
DEVELOCITY_CCUD_PLUGIN_VERSION: 1.12.1
|
DEVELOCITY_CCUD_PLUGIN_VERSION: '2.0'
|
||||||
GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }} # This env var has not (yet) been renamed/aliased in GE plugin 3.16.2
|
${{matrix.accessKeyEnv}}: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
gradle: [current, 7.6.2, 6.9.4, 5.6.4]
|
gradle: [current, 7.6.2, 6.9.4, 5.6.4]
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ubuntu-latest
|
plugin-version: [3.16.2, 3.17.6]
|
||||||
|
include:
|
||||||
|
- plugin-version: 3.16.2
|
||||||
|
accessKeyEnv: GRADLE_ENTERPRISE_ACCESS_KEY
|
||||||
|
- plugin-version: 3.17.6
|
||||||
|
accessKeyEnv: DEVELOCITY_ACCESS_KEY
|
||||||
|
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java
|
- name: Setup Java
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: temurin
|
distribution: temurin
|
||||||
java-version: 8
|
java-version: 11
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
id: setup-gradle
|
id: setup-gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
@@ -57,40 +66,136 @@ jobs:
|
|||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v7
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
core.setFailed('No Build Scan detected')
|
core.setFailed('No Build Scan detected')
|
||||||
|
- name: Check short lived token (DEVELOCITY_ACCESS_KEY)
|
||||||
|
run: "[ ${#DEVELOCITY_ACCESS_KEY} -gt 500 ] || (echo 'DEVELOCITY_ACCESS_KEY does not look like a short lived token'; exit 1)"
|
||||||
|
- name: Check short lived token (GRADLE_ENTERPRISE_ACCESS_KEY)
|
||||||
|
run: "[ ${#GRADLE_ENTERPRISE_ACCESS_KEY} -gt 500 ] || (echo 'GRADLE_ENTERPRISE_ACCESS_KEY does not look like a short lived token'; exit 1)"
|
||||||
|
|
||||||
build-scan-publish:
|
inject-develocity-with-access-key:
|
||||||
|
env:
|
||||||
|
DEVELOCITY_INJECTION_ENABLED: true
|
||||||
|
DEVELOCITY_URL: 'https://ge.solutions-team.gradle.com'
|
||||||
|
DEVELOCITY_PLUGIN_VERSION: ${{ matrix.plugin-version }}
|
||||||
|
DEVELOCITY_CCUD_PLUGIN_VERSION: '2.0'
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
gradle: [current, 7.6.2, 6.9.4, 5.6.4]
|
gradle: [current, 7.6.2, 6.9.4, 5.6.4]
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
plugin-version: [3.16.2, 3.17.6]
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 8
|
||||||
|
- name: Setup Gradle
|
||||||
|
id: setup-gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
gradle-version: ${{ matrix.gradle }}
|
||||||
|
develocity-access-key: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
develocity-token-expiry: 1
|
||||||
|
- name: Run Gradle build
|
||||||
|
id: gradle
|
||||||
|
working-directory: .github/workflow-samples/no-ge
|
||||||
|
run: gradle help
|
||||||
|
- name: Check short lived token (DEVELOCITY_ACCESS_KEY)
|
||||||
|
run: "[ ${#DEVELOCITY_ACCESS_KEY} -gt 500 ] || (echo 'DEVELOCITY_ACCESS_KEY does not look like a short lived token'; exit 1)"
|
||||||
|
- name: Check short lived token (GRADLE_ENTERPRISE_ACCESS_KEY)
|
||||||
|
run: "[ ${#GRADLE_ENTERPRISE_ACCESS_KEY} -gt 500 ] || (echo 'GRADLE_ENTERPRISE_ACCESS_KEY does not look like a short lived token'; exit 1)"
|
||||||
|
- name: Check Build Scan url
|
||||||
|
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
||||||
|
uses: actions/github-script@v7
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
core.setFailed('No Build Scan detected')
|
||||||
|
|
||||||
|
inject-develocity-short-lived-token-failed:
|
||||||
|
env:
|
||||||
|
DEVELOCITY_INJECTION_ENABLED: true
|
||||||
|
DEVELOCITY_URL: 'https://localhost:3333/'
|
||||||
|
DEVELOCITY_PLUGIN_VERSION: ${{ matrix.plugin-version }}
|
||||||
|
DEVELOCITY_CCUD_PLUGIN_VERSION: '2.0'
|
||||||
|
# Access key also set as an env var, we want to check it does not leak
|
||||||
|
GRADLE_ENTERPRISE_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
gradle: [ current, 7.6.2, 6.9.4, 5.6.4 ]
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
plugin-version: [ 3.16.2, 3.17.6 ]
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
- name: Setup Java
|
|
||||||
uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
distribution: temurin
|
|
||||||
java-version: 8
|
|
||||||
- name: Setup Gradle
|
|
||||||
id: setup-gradle
|
|
||||||
uses: ./setup-gradle
|
|
||||||
with:
|
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
|
||||||
gradle-version: ${{ matrix.gradle }}
|
|
||||||
build-scan-publish: true
|
|
||||||
build-scan-terms-of-service-url: "https://gradle.com/terms-of-service"
|
|
||||||
build-scan-terms-of-service-agree: "yes"
|
|
||||||
- name: Run Gradle build
|
|
||||||
id: gradle
|
|
||||||
working-directory: .github/workflow-samples/no-ge
|
|
||||||
run: gradle help
|
|
||||||
- name: Check Build Scan url
|
|
||||||
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
|
||||||
uses: actions/github-script@v7
|
|
||||||
with:
|
|
||||||
script: |
|
|
||||||
core.setFailed('No Build Scan detected')
|
|
||||||
|
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 8
|
||||||
|
- name: Setup Gradle
|
||||||
|
id: setup-gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
develocity-access-key: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
- name: Run Gradle build
|
||||||
|
id: gradle
|
||||||
|
working-directory: .github/workflow-samples/no-ge
|
||||||
|
run: gradle help
|
||||||
|
- name: Check access key is not blank (DEVELOCITY_ACCESS_KEY)
|
||||||
|
run: "[ \"${DEVELOCITY_ACCESS_KEY}\" != \"\" ] || (echo 'using DEVELOCITY_ACCESS_KEY!'; exit 1)"
|
||||||
|
- name: Check access key is not blank (GRADLE_ENTERPRISE_ACCESS_KEY)
|
||||||
|
run: "[ \"${GRADLE_ENTERPRISE_ACCESS_KEY}\" != \"\" ] || (echo 'GRADLE_ENTERPRISE_ACCESS_KEY is still supported in v3!'; exit 1)"
|
||||||
|
|
||||||
|
inject-develocity-with-access-key-from-input-actions:
|
||||||
|
env:
|
||||||
|
DEVELOCITY_ACCESS_KEY: ${{ secrets.DEVELOCITY_ACCESS_KEY }}
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
gradle: [ current, 7.6.2, 6.9.4, 5.6.4 ]
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
plugin-version: [ 3.16.2, 3.17.6 ]
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 8
|
||||||
|
- name: Setup Gradle
|
||||||
|
id: setup-gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
gradle-version: ${{ matrix.gradle }}
|
||||||
|
develocity-injection-enabled: true
|
||||||
|
develocity-url: 'https://ge.solutions-team.gradle.com'
|
||||||
|
develocity-plugin-version: ${{ matrix.plugin-version }}
|
||||||
|
- name: Run Gradle build
|
||||||
|
id: gradle
|
||||||
|
working-directory: .github/workflow-samples/no-ge
|
||||||
|
run: gradle help
|
||||||
|
- name: Check Build Scan url
|
||||||
|
if: ${{ !steps.gradle.outputs.build-scan-url }}
|
||||||
|
uses: actions/github-script@v7
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
core.setFailed('No Build Scan detected')
|
||||||
|
|||||||
@@ -8,12 +8,12 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: provision-gradle-versions-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: provision-gradle-versions-${{ inputs.cache-key-prefix }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_DEBUG_ENABLED: true
|
GRADLE_BUILD_ACTION_CACHE_DEBUG_ENABLED: true
|
||||||
|
|
||||||
@@ -22,17 +22,16 @@ jobs:
|
|||||||
# Each build verifies that it is executed with the expected Gradle version.
|
# Each build verifies that it is executed with the expected Gradle version.
|
||||||
provision-gradle:
|
provision-gradle:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
include:
|
|
||||||
- os: windows-latest
|
|
||||||
script-suffix: '.bat'
|
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle with v6.9
|
- name: Setup Gradle with v6.9
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -60,6 +59,9 @@ jobs:
|
|||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
gradle-version: current
|
gradle-version: current
|
||||||
|
- name: Test use current
|
||||||
|
working-directory: .github/workflow-samples/no-wrapper
|
||||||
|
run: gradle help
|
||||||
- name: Check current version output parameter
|
- name: Check current version output parameter
|
||||||
if: ${{ !startsWith(steps.gradle-current.outputs.gradle-version , '8.') }}
|
if: ${{ !startsWith(steps.gradle-current.outputs.gradle-version , '8.') }}
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v7
|
||||||
@@ -69,27 +71,34 @@ jobs:
|
|||||||
|
|
||||||
gradle-versions:
|
gradle-versions:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
gradle: [7.3, 6.9, 5.6.4, 4.10.3, 3.5.1]
|
gradle: [8.9, 8.8, 7.6.4, 6.9.4, 5.6.4, 4.10.3, 3.5.1] # 8.8 is the latest installed on windows runners
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
include:
|
include:
|
||||||
|
- java-version: 11
|
||||||
- gradle: 5.6.4
|
- gradle: 5.6.4
|
||||||
build-root-suffix: -gradle-5
|
build-root-suffix: -gradle-5
|
||||||
- gradle: 4.10.3
|
- gradle: 4.10.3
|
||||||
build-root-suffix: -gradle-4
|
build-root-suffix: -gradle-4
|
||||||
- gradle: 3.5.1
|
- gradle: 3.5.1
|
||||||
build-root-suffix: -gradle-4
|
build-root-suffix: -gradle-4
|
||||||
|
java-version: 8
|
||||||
|
exclude:
|
||||||
|
- os: macos-latest # Java 8 is not supported on macos-latest, so we cannot test Gradle 3.5.1
|
||||||
|
gradle: 3.5.1
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java
|
- name: Setup Java
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: temurin
|
distribution: temurin
|
||||||
java-version: 8
|
java-version: ${{ matrix.java-version }}
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
id: setup-gradle
|
id: setup-gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
secrets:
|
secrets:
|
||||||
@@ -16,7 +16,7 @@ on:
|
|||||||
required: true
|
required: true
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-configuration-cache-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-configuration-cache-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
@@ -24,23 +24,26 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
cache-write-only: true # Ensure we start with a clean cache entry
|
||||||
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
||||||
gradle-version: 8.6
|
gradle-version: 8.6
|
||||||
- name: Groovy build with configuration-cache enabled
|
- name: Groovy build with configuration-cache enabled
|
||||||
@@ -50,21 +53,65 @@ jobs:
|
|||||||
verify-build-groovy:
|
verify-build-groovy:
|
||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB_EXECUTION: ${{github.sha}}_1
|
||||||
needs: seed-build-groovy
|
needs: seed-build-groovy
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
with:
|
||||||
|
cache-read-only: false
|
||||||
|
cache-cleanup: on-success
|
||||||
|
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
||||||
|
gradle-version: 8.6
|
||||||
|
- name: Groovy build with configuration-cache enabled
|
||||||
|
id: execute
|
||||||
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
|
run: gradle test --configuration-cache
|
||||||
|
- name: Verify configuration-cache hit
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [ -e ".github/workflow-samples/groovy-dsl/task-configured.txt" ]; then
|
||||||
|
echo "Configuration cache was not used - task was configured unexpectedly"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Ensure that cache-cleanup doesn't remove all necessary files
|
||||||
|
verify-no-cache-cleanup-groovy:
|
||||||
|
env:
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB_EXECUTION: ${{github.sha}}_2
|
||||||
|
needs: verify-build-groovy
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Setup Java to ensure consistency
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: 'liberica'
|
||||||
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -75,34 +122,36 @@ jobs:
|
|||||||
id: execute
|
id: execute
|
||||||
working-directory: .github/workflow-samples/groovy-dsl
|
working-directory: .github/workflow-samples/groovy-dsl
|
||||||
run: gradle test --configuration-cache
|
run: gradle test --configuration-cache
|
||||||
- name: Check that configuration-cache was used
|
- name: Verify configuration-cache hit
|
||||||
uses: actions/github-script@v7
|
shell: bash
|
||||||
with:
|
run: |
|
||||||
script: |
|
if [ -e ".github/workflow-samples/groovy-dsl/task-configured.txt" ]; then
|
||||||
const fs = require('fs')
|
echo "Configuration cache was not used - task was configured unexpectedly"
|
||||||
if (fs.existsSync('.github/workflow-samples/groovy-dsl/task-configured.txt')) {
|
exit 1
|
||||||
core.setFailed('Configuration cache was not used - task was configured unexpectedly')
|
fi
|
||||||
}
|
|
||||||
|
|
||||||
# Check that the build can run when no extracted cache entries are restored
|
# Check that the build can run when no extracted cache entries are restored
|
||||||
gradle-user-home-not-fully-restored:
|
gradle-user-home-not-fully-restored:
|
||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-groovy
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB_EXECUTION: ${{github.sha}}_x
|
||||||
needs: seed-build-groovy
|
needs: seed-build-groovy
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
- name: Setup Gradle with no extracted cache entries restored
|
- name: Setup Gradle with no extracted cache entries restored
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
env:
|
env:
|
||||||
@@ -119,23 +168,26 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
cache-read-only: false # For testing, allow writing cache entries on non-default branches
|
||||||
|
cache-write-only: true # Ensure we start with a clean cache entry
|
||||||
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
||||||
gradle-version: 8.6
|
gradle-version: 8.6
|
||||||
- name: Execute 'help' with configuration-cache enabled
|
- name: Execute 'help' with configuration-cache enabled
|
||||||
@@ -144,22 +196,25 @@ jobs:
|
|||||||
|
|
||||||
modify-build-kotlin:
|
modify-build-kotlin:
|
||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin-modified
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB_EXECUTION: ${{github.sha}}_1
|
||||||
needs: seed-build-kotlin
|
needs: seed-build-kotlin
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -173,22 +228,25 @@ jobs:
|
|||||||
# Test restore configuration-cache from the third build invocation
|
# Test restore configuration-cache from the third build invocation
|
||||||
verify-build-kotlin:
|
verify-build-kotlin:
|
||||||
env:
|
env:
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin-modified
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-cc-kotlin
|
||||||
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB_EXECUTION: ${{github.sha}}_2
|
||||||
needs: modify-build-kotlin
|
needs: modify-build-kotlin
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Java to ensure consistency
|
- name: Setup Java to ensure consistency
|
||||||
uses: actions/setup-java@v4
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
distribution: 'liberica'
|
distribution: 'liberica'
|
||||||
java-version: '21'
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -199,12 +257,10 @@ jobs:
|
|||||||
id: execute
|
id: execute
|
||||||
working-directory: .github/workflow-samples/kotlin-dsl
|
working-directory: .github/workflow-samples/kotlin-dsl
|
||||||
run: gradle test --configuration-cache
|
run: gradle test --configuration-cache
|
||||||
- name: Check that configuration-cache was used
|
- name: Verify configuration-cache hit
|
||||||
uses: actions/github-script@v7
|
shell: bash
|
||||||
with:
|
run: |
|
||||||
script: |
|
if [ -e ".github/workflow-samples/kotlin-dsl/task-configured.txt" ]; then
|
||||||
const fs = require('fs')
|
echo "Configuration cache was not used - task was configured unexpectedly"
|
||||||
if (fs.existsSync('.github/workflow-samples/kotlin-dsl/task-configured.txt')) {
|
exit 1
|
||||||
core.setFailed('Configuration cache was not used - task was configured unexpectedly')
|
fi
|
||||||
}
|
|
||||||
|
|
||||||
|
|||||||
@@ -5,13 +5,13 @@ on:
|
|||||||
inputs:
|
inputs:
|
||||||
cache-key-prefix:
|
cache-key-prefix:
|
||||||
type: string
|
type: string
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-custom-gradle-home-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-containerized-gradle-home-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
@@ -20,13 +20,9 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
- name: Setup Java
|
|
||||||
uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
java-version: 11
|
|
||||||
distribution: temurin
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -43,13 +39,9 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
- name: Setup Java
|
|
||||||
uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
java-version: 11
|
|
||||||
distribution: temurin
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -5,26 +5,27 @@ on:
|
|||||||
inputs:
|
inputs:
|
||||||
cache-key-prefix:
|
cache-key-prefix:
|
||||||
type: string
|
type: string
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-custom-gradle-home-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-custom-gradle-home-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Set Gradle User Home
|
- name: Set Gradle User Home
|
||||||
run: |
|
run: |
|
||||||
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
||||||
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -38,14 +39,15 @@ jobs:
|
|||||||
needs: seed-build
|
needs: seed-build
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Set Gradle User Home
|
- name: Set Gradle User Home
|
||||||
run: |
|
run: |
|
||||||
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
||||||
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -59,14 +61,15 @@ jobs:
|
|||||||
needs: seed-build
|
needs: seed-build
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Set Gradle User Home
|
- name: Set Gradle User Home
|
||||||
run: |
|
run: |
|
||||||
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
mkdir -p $GITHUB_WORKSPACE/gradle-user-home
|
||||||
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
echo "GRADLE_USER_HOME=$GITHUB_WORKSPACE/gradle-user-home" >> $GITHUB_ENV
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Download distribution if required
|
|
||||||
uses: ./.github/actions/download-dist
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -8,26 +8,28 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-gradle-home-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-gradle-home-${{ inputs.cache-key-prefix }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-gradle-home
|
GRADLE_BUILD_ACTION_CACHE_KEY_JOB: restore-gradle-home
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -40,14 +42,16 @@ jobs:
|
|||||||
dependencies-cache:
|
dependencies-cache:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -60,14 +64,16 @@ jobs:
|
|||||||
build-cache:
|
build-cache:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -80,14 +86,16 @@ jobs:
|
|||||||
no-extracted-cache-entries-restored:
|
no-extracted-cache-entries-restored:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle with no extracted cache entries restored
|
- name: Setup Gradle with no extracted cache entries restored
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
env:
|
env:
|
||||||
@@ -102,14 +110,16 @@ jobs:
|
|||||||
pre-existing-gradle-home:
|
pre-existing-gradle-home:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Pre-create Gradle User Home
|
- name: Pre-create Gradle User Home
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -8,25 +8,27 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-java-toolchain-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: restore-java-toolchain-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -39,14 +41,16 @@ jobs:
|
|||||||
toolchain-cache:
|
toolchain-cache:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -8,25 +8,27 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: sample-gradle-plugin-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: sample-gradle-plugin-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -38,14 +40,16 @@ jobs:
|
|||||||
verify-build:
|
verify-build:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -8,25 +8,27 @@ on:
|
|||||||
runner-os:
|
runner-os:
|
||||||
type: string
|
type: string
|
||||||
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
download-dist:
|
skip-dist:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DOWNLOAD_DIST: ${{ inputs.download-dist }}
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: sample-kotlin-dsl-${{ inputs.cache-key-prefix }}
|
GRADLE_BUILD_ACTION_CACHE_KEY_PREFIX: sample-kotlin-dsl-${{ inputs.cache-key-prefix }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
seed-build:
|
seed-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
@@ -38,14 +40,16 @@ jobs:
|
|||||||
verify-build:
|
verify-build:
|
||||||
needs: seed-build
|
needs: seed-build
|
||||||
strategy:
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
os: ${{fromJSON(inputs.runner-os)}}
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
- name: Download distribution if required
|
- name: Initialize integ-test
|
||||||
uses: ./.github/actions/download-dist
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: ./setup-gradle
|
uses: ./setup-gradle
|
||||||
with:
|
with:
|
||||||
|
|||||||
100
.github/workflows/integ-test-wrapper-validation.yml
vendored
Normal file
100
.github/workflows/integ-test-wrapper-validation.yml
vendored
Normal file
@@ -0,0 +1,100 @@
|
|||||||
|
name: Test wrapper validation
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
runner-os:
|
||||||
|
type: string
|
||||||
|
default: '["ubuntu-latest", "windows-latest", "macos-latest"]'
|
||||||
|
skip-dist:
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
SKIP_DIST: ${{ inputs.skip-dist }}
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test-setup-gradle-validation:
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
os: ${{fromJSON(inputs.runner-os)}}
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Run wrapper-validation-action
|
||||||
|
id: setup-gradle
|
||||||
|
uses: ./setup-gradle
|
||||||
|
env:
|
||||||
|
ALLOWED_GRADLE_WRAPPER_CHECKSUMS: ''
|
||||||
|
continue-on-error: true
|
||||||
|
|
||||||
|
- name: Check failure
|
||||||
|
run: |
|
||||||
|
if [ "${{ steps.setup-gradle.outcome}}" != "failure" ] ; then
|
||||||
|
echo "Expected validation to fail, but it didn't"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
test-validation-success:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Run wrapper-validation-action
|
||||||
|
id: action-test
|
||||||
|
uses: ./wrapper-validation
|
||||||
|
with:
|
||||||
|
# to allow the invalid wrapper jar present in test data
|
||||||
|
allow-checksums: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
||||||
|
|
||||||
|
- name: Check outcome
|
||||||
|
env:
|
||||||
|
# Evaluate workflow expressions here as env variable values instead of inside shell script
|
||||||
|
# below to not accidentally inject code into shell script or break its syntax
|
||||||
|
FAILED_WRAPPERS: ${{ steps.action-test.outputs.failed-wrapper }}
|
||||||
|
FAILED_WRAPPERS_MATCHES: ${{ steps.action-test.outputs.failed-wrapper == '' }}
|
||||||
|
run: |
|
||||||
|
if [ "$FAILED_WRAPPERS_MATCHES" != "true" ] ; then
|
||||||
|
echo "'outputs.failed-wrapper' has unexpected content: $FAILED_WRAPPERS"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
test-validation-error:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Initialize integ-test
|
||||||
|
uses: ./.github/actions/init-integ-test
|
||||||
|
|
||||||
|
- name: Run wrapper-validation-action
|
||||||
|
id: action-test
|
||||||
|
uses: ./wrapper-validation
|
||||||
|
# Expected to fail; validated below
|
||||||
|
continue-on-error: true
|
||||||
|
|
||||||
|
- name: Check outcome
|
||||||
|
env:
|
||||||
|
# Evaluate workflow expressions here as env variable values instead of inside shell script
|
||||||
|
# below to not accidentally inject code into shell script or break its syntax
|
||||||
|
VALIDATION_FAILED: ${{ steps.action-test.outcome == 'failure' }}
|
||||||
|
FAILED_WRAPPERS: ${{ steps.action-test.outputs.failed-wrapper }}
|
||||||
|
FAILED_WRAPPERS_MATCHES: ${{ steps.action-test.outputs.failed-wrapper == 'sources/test/jest/wrapper-validation/data/invalid/gradle-wrapper.jar|sources/test/jest/wrapper-validation/data/invalid/gradlе-wrapper.jar' }}
|
||||||
|
run: |
|
||||||
|
if [ "$VALIDATION_FAILED" != "true" ] ; then
|
||||||
|
echo "Expected validation to fail, but it didn't"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$FAILED_WRAPPERS_MATCHES" != "true" ] ; then
|
||||||
|
echo "'outputs.failed-wrapper' has unexpected content: $FAILED_WRAPPERS"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
94
.github/workflows/update-checksums-file.js
vendored
Normal file
94
.github/workflows/update-checksums-file.js
vendored
Normal file
@@ -0,0 +1,94 @@
|
|||||||
|
/*
|
||||||
|
* Updates the `wrapper-checksums.json` file
|
||||||
|
*
|
||||||
|
* This is intended to be executed by the GitHub workflow, but can also be run
|
||||||
|
* manually.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// @ts-check
|
||||||
|
|
||||||
|
const httpm = require('../../sources/node_modules/typed-rest-client/HttpClient')
|
||||||
|
|
||||||
|
const path = require('path')
|
||||||
|
const fs = require('fs')
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async function main() {
|
||||||
|
const httpc = new httpm.HttpClient(
|
||||||
|
'gradle/wrapper-validation-action/update-checksums-workflow',
|
||||||
|
undefined,
|
||||||
|
{allowRetries: true, maxRetries: 3}
|
||||||
|
)
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {string} url
|
||||||
|
* @returns {Promise<string>}
|
||||||
|
*/
|
||||||
|
async function httpGetText(url) {
|
||||||
|
const response = await httpc.get(url)
|
||||||
|
return await response.readBody()
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} ApiVersionEntry
|
||||||
|
* @property {string} version - version name
|
||||||
|
* @property {string=} wrapperChecksumUrl - wrapper checksum URL; not present for old versions
|
||||||
|
* @property {boolean} snapshot - whether this is a snapshot version
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @returns {Promise<ApiVersionEntry[]>}
|
||||||
|
*/
|
||||||
|
async function httpGetVersions() {
|
||||||
|
return JSON.parse(
|
||||||
|
await httpGetText('https://services.gradle.org/versions/all')
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
const versions = (await httpGetVersions())
|
||||||
|
// Only include versions with checksum
|
||||||
|
.filter(e => e.wrapperChecksumUrl !== undefined)
|
||||||
|
// Ignore snapshots; they are changing frequently so no point in including them in checksums file
|
||||||
|
.filter(e => !e.snapshot)
|
||||||
|
console.info(`Got ${versions.length} relevant Gradle versions`)
|
||||||
|
|
||||||
|
// Note: For simplicity don't sort the entries but keep the order from the API; this also has the
|
||||||
|
// advantage that the latest versions come first, so compared to appending versions at the end
|
||||||
|
// this will not cause redundant Git diff due to trailing `,` being forbidden by JSON
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} FileVersionEntry
|
||||||
|
* @property {string} version
|
||||||
|
* @property {string} checksum
|
||||||
|
*/
|
||||||
|
/** @type {FileVersionEntry[]} */
|
||||||
|
const fileVersions = []
|
||||||
|
for (const entry of versions) {
|
||||||
|
/** @type {string} */
|
||||||
|
// @ts-ignore
|
||||||
|
const checksumUrl = entry.wrapperChecksumUrl
|
||||||
|
const checksum = await httpGetText(checksumUrl)
|
||||||
|
fileVersions.push({version: entry.version, checksum})
|
||||||
|
}
|
||||||
|
|
||||||
|
const jsonPath = path.resolve(
|
||||||
|
__dirname,
|
||||||
|
'..',
|
||||||
|
'..',
|
||||||
|
'sources',
|
||||||
|
'src',
|
||||||
|
'wrapper-validation',
|
||||||
|
'wrapper-checksums.json'
|
||||||
|
)
|
||||||
|
console.info(`Writing checksums file to ${jsonPath}`)
|
||||||
|
// Write pretty-printed JSON (and add trailing line break)
|
||||||
|
fs.writeFileSync(jsonPath, JSON.stringify(fileVersions, null, 2) + '\n')
|
||||||
|
}
|
||||||
|
|
||||||
|
main().catch(e => {
|
||||||
|
console.error(e)
|
||||||
|
// Manually set error exit code, otherwise error is logged but script exits successfully
|
||||||
|
process.exitCode = 1
|
||||||
|
})
|
||||||
55
.github/workflows/update-checksums-file.yml
vendored
Normal file
55
.github/workflows/update-checksums-file.yml
vendored
Normal file
@@ -0,0 +1,55 @@
|
|||||||
|
name: 'Update Wrapper checksums file'
|
||||||
|
|
||||||
|
on:
|
||||||
|
# Run weekly (at arbitrary time)
|
||||||
|
schedule:
|
||||||
|
- cron: '24 5 * * 6'
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
pull-requests: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
update-checksums:
|
||||||
|
name: Update checksums
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Set up Node.js
|
||||||
|
uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: npm
|
||||||
|
cache-dependency-path: sources/package-lock.json
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: |
|
||||||
|
npm install typed-rest-client@1.8.11 --no-save
|
||||||
|
working-directory: sources
|
||||||
|
|
||||||
|
- name: Update checksums file
|
||||||
|
run: node ../.github/workflows/update-checksums-file.js
|
||||||
|
working-directory: sources
|
||||||
|
|
||||||
|
# If there are no changes, this action will not create a pull request
|
||||||
|
- name: Create or update pull request
|
||||||
|
uses: peter-evans/create-pull-request@v6
|
||||||
|
with:
|
||||||
|
branch: bot/wrapper-checksums-update
|
||||||
|
commit-message: Update known wrapper checksums
|
||||||
|
title: Update known wrapper checksums
|
||||||
|
# Note: Unfortunately this action cannot trigger the regular workflows for the PR automatically, see
|
||||||
|
# https://github.com/peter-evans/create-pull-request/blob/main/docs/concepts-guidelines.md#triggering-further-workflow-runs
|
||||||
|
# Therefore suggest below to close and then reopen the PR
|
||||||
|
body: |
|
||||||
|
Automatically generated pull request to update the known wrapper checksums.
|
||||||
|
|
||||||
|
In case of conflicts, manually run the workflow from the [Actions tab](https://github.com/gradle/actions/actions/workflows/update-checksums-file.yml), the changes will then be force-pushed onto this pull request branch.
|
||||||
|
Do not manually update the pull request branch; those changes might get overwritten.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> GitHub workflows have not been executed for this pull request yet. Before merging, close and then directly reopen this pull request to trigger the workflows.
|
||||||
2
.gitignore
vendored
Normal file
2
.gitignore
vendored
Normal file
@@ -0,0 +1,2 @@
|
|||||||
|
.git
|
||||||
|
.vscode
|
||||||
@@ -1,14 +1,33 @@
|
|||||||
### How to merge a Dependabot PR
|
## Building
|
||||||
|
|
||||||
The "distribution" for a GitHub Action is checked into the repository itself.
|
The `build` script in the project root provides a convenient way to perform many local build tasks:
|
||||||
In the case of these actions, the transpiled sources are committed to the `dist` directory.
|
1. `./build` will lint and compile typescript sources
|
||||||
Any production dependencies are inlined into the distribution.
|
2. `./build all` will lint and compile typescript and run unit tests
|
||||||
So if a Dependabot PR updates a production dependency (or a dev dependency that changes the distribution, like the Typescript compiler),
|
3. `./build init-scripts` will run the init-script integration tests
|
||||||
then a manual step is required to rebuild the dist and commit.
|
4. `./build act <act-commands>` will run `act` after building local changes (see below)
|
||||||
|
|
||||||
The simplest process to follow is:
|
## Using `act` to run integ-test workflows locally
|
||||||
1. Checkout the dependabot branch locally eg: `git checkout dependabot/npm_and_yarn/actions/github-5.1.0`
|
|
||||||
2. In the `sources` directory, run `npm install` to download NPM dependencies
|
It's possible to run GitHub Actions workflows locally with https://nektosact.com/.
|
||||||
3. In the `sources` directory, run `npm run build` to regenerate the distribution
|
Many of the test workflows from this repository can be run in this way, making it easier to
|
||||||
4. Push the changes to the dependabot branch
|
test local changes without pushing to a branch.
|
||||||
5. If/when the checks pass, you can merge the dependabot PR
|
|
||||||
|
This feature is most useful to run a single `integ-test-*` workflow. Avoid running `ci-quick-test` or other aggregating workflows unless you want to use your local machine as a heater!
|
||||||
|
|
||||||
|
Example running a single workflow:
|
||||||
|
`./build act -W .github/workflows/integ-test-caching-config.yml`
|
||||||
|
|
||||||
|
Example running a single job:
|
||||||
|
`./build act -W .github/workflows/integ-test-caching-config.yml -j cache-disabled-pre-existing-gradle-home`
|
||||||
|
|
||||||
|
Known issues:
|
||||||
|
- `integ-test-detect-java-toolchains.yml` fails when running on a `linux/amd64` container, since the expected pre-installed JDKs are not present. Should be fixed by #89.
|
||||||
|
- `act` is not yet compatible with `actions/upload-artifact@v4` (or related toolkit functions)
|
||||||
|
- See https://github.com/nektos/act/pull/2224
|
||||||
|
- Workflows run by `act` cannot submit to the dependency-submission API, as no `GITHUB_TOKEN` is available by default.
|
||||||
|
|
||||||
|
Tips:
|
||||||
|
- Add the following lines to `~/.actrc`:
|
||||||
|
- `--container-daemon-socket -` : Prevents "error while creating mount source path", and yes that's a solitary dash at the end
|
||||||
|
- `--matrix os:ubuntu-latest` : Avoids a lot of logging about unsupported runners being skipped
|
||||||
|
- Runners don't have `java` installed by default, so all workflows that run Gradle require a `setup-java` step.
|
||||||
|
|||||||
51
README.md
51
README.md
@@ -4,14 +4,19 @@ This repository contains a set of GitHub Actions that are useful for building Gr
|
|||||||
|
|
||||||
## The `setup-gradle` action
|
## The `setup-gradle` action
|
||||||
|
|
||||||
|
The `setup-gradle` action can be used to configure Gradle for optimal execution on any platform supported by GitHub Actions.
|
||||||
|
|
||||||
This replaces the previous `gradle/gradle-build-action`, which now delegates to this implementation.
|
This replaces the previous `gradle/gradle-build-action`, which now delegates to this implementation.
|
||||||
|
|
||||||
|
The recommended way to execute any Gradle build is with the help of the [Gradle Wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html), and the examples assume that the Gradle Wrapper has been configured for the project. See [this example](docs/setup-gradle.md#build-with-a-specific-gradle-version) if your project doesn't use the Gradle Wrapper.
|
||||||
|
|
||||||
### Example usage
|
### Example usage
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: Build
|
name: Build
|
||||||
|
|
||||||
on: [ push ]
|
on:
|
||||||
|
push:
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
@@ -19,13 +24,18 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: 'temurin'
|
||||||
|
java-version: 17
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: gradle/actions/setup-gradle@v3
|
uses: gradle/actions/setup-gradle@v3
|
||||||
- name: Build with Gradle
|
- name: Build with Gradle
|
||||||
run: ./gradlew build
|
run: ./gradlew build
|
||||||
```
|
```
|
||||||
|
|
||||||
See the [full action documentation](setup-gradle/README.md) for more advanced usage scenarios.
|
See the [full action documentation](docs/setup-gradle.md) for more advanced usage scenarios.
|
||||||
|
|
||||||
## The `dependency-submission` action
|
## The `dependency-submission` action
|
||||||
|
|
||||||
@@ -39,7 +49,9 @@ Simply add this as a new workflow file to your repository (eg `.github/workflows
|
|||||||
```yaml
|
```yaml
|
||||||
name: Dependency Submission
|
name: Dependency Submission
|
||||||
|
|
||||||
on: [ push ]
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ 'main' ]
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
@@ -50,8 +62,39 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: 'temurin'
|
||||||
|
java-version: 17
|
||||||
- name: Generate and submit dependency graph
|
- name: Generate and submit dependency graph
|
||||||
uses: gradle/actions/dependency-submission@v3
|
uses: gradle/actions/dependency-submission@v3
|
||||||
```
|
```
|
||||||
|
|
||||||
See the [full action documentation](dependency-submission/README.md) for more advanced usage scenarios.
|
See the [full action documentation](docs/dependency-submission.md) for more advanced usage scenarios.
|
||||||
|
|
||||||
|
## The `wrapper-validation` action
|
||||||
|
|
||||||
|
The `wrapper-validation` action validates the checksums of _all_ [Gradle Wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html) JAR files present in the repository and fails if any unknown Gradle Wrapper JAR files are found.
|
||||||
|
|
||||||
|
The action should be run in the root of the repository, as it will recursively search for any files named `gradle-wrapper.jar`.
|
||||||
|
|
||||||
|
### Example workflow
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: "Validate Gradle Wrapper"
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
validation:
|
||||||
|
name: "Validation"
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: gradle/actions/wrapper-validation@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
See the [full action documentation](docs/wrapper-validation.md) for more advanced usage scenarios.
|
||||||
|
|||||||
62
RELEASING.md
Normal file
62
RELEASING.md
Normal file
@@ -0,0 +1,62 @@
|
|||||||
|
# Gradle GitHub Actions release process
|
||||||
|
|
||||||
|
## Preparation
|
||||||
|
- Push any outstanding changes to branch main.
|
||||||
|
- Check that https://github.com/gradle/actions/actions is green for all workflows for the main branch.
|
||||||
|
- This should include any workflows triggered by `[bot] Update dist directory`
|
||||||
|
- Decide on the version number to use for the release. The action releases should follow semantic versioning.
|
||||||
|
- By default, a patch release is assumed (eg. `3.0.0` → `3.0.1`)
|
||||||
|
- If new features have been added, bump the minor version (eg `3.1.1` → `3.2.0`)
|
||||||
|
- If a new major release is required, bump the major version (eg `3.1.1` → `4.0.0`)
|
||||||
|
- Note: The gradle actions follow the GitHub Actions convention of including a .0 patch number for the first release of a minor version, unlike the Gradle convention which omits the trailing .0.
|
||||||
|
|
||||||
|
## Release gradle/actions
|
||||||
|
- Create a tag for the release. The tag should have the format `v3.1.0`
|
||||||
|
- From CLI: `git tag v3.1.0 && git push --tags`
|
||||||
|
- Go to https://github.com/gradle/actions/releases and "Draft new release"
|
||||||
|
- Use the newly created tag and copy the tag name exactly as the release title.
|
||||||
|
- Craft release notes content based on issues closed, PRs merged and commits
|
||||||
|
- Include a Full changelog link in the format https://github.com/gradle/actions/compare/v2.12.0...v3.0.0
|
||||||
|
- Publish the release.
|
||||||
|
- Force push the `v3` tag (or current major version) to point to the new release. It is conventional for users to bind to a major release version using this tag.
|
||||||
|
- From CLI: `git tag -f -a -m "v3.0.0" v3 v3.0.0 && git push -f --tags`
|
||||||
|
- Note that we set the commit message for the tag to the newly released version.
|
||||||
|
|
||||||
|
## Release gradle/gradle-build-action
|
||||||
|
|
||||||
|
During the 3.x release series, we will continue to publish parallel releases of `gradle/gradle-build-action`. These releases will simply delegate to `gradle/actions/setup-gradle` with the same version.
|
||||||
|
|
||||||
|
- Update the [gradle-build-action action.yml](https://github.com/gradle/gradle-build-action/blob/main/action.yml#L162) file to point to the newly released version of `gradle/actions/setup-gradle`.
|
||||||
|
- Ensure that any parameters that have been added to the setup-gradle action are added to the gradle-build-action definition, and that these are passed on to setup-gradle.
|
||||||
|
- Create and push a tag for the release.
|
||||||
|
- From CLI: `git tag v3.1.0 && git push --tags`
|
||||||
|
- Go to https://github.com/gradle/gradle-build-action/releases and "Draft new release"
|
||||||
|
- Use the newly created tag and copy the tag name exactly as the release title.
|
||||||
|
- In the release notes, point users to the gradle/actions release. Include a header informing users to switch to `gradle/actions/setup-gradle`.
|
||||||
|
- Publish the release.
|
||||||
|
- Force push the `v3` tag (or current major version) to point to the new release.
|
||||||
|
- From CLI: `git tag -f -a -m "v3.0.0" v3 v3.0.0 && git push -f --tags`
|
||||||
|
|
||||||
|
## Release gradle/wrapper-validation-action
|
||||||
|
|
||||||
|
During the 3.x release series, we will continue to publish parallel releases of `gradle/wrapper-validation-action`. These releases will simply delegate to `gradle/actions/wrapper-validation` with the same version.
|
||||||
|
|
||||||
|
- Update the [wrapper-validation-action action.yml](https://github.com/gradle/wrapper-validation-action/blob/main/action.yml#L162) file to point to the newly released version of `gradle/actions/wrapper-validation`.
|
||||||
|
- Ensure that any parameters that have been added to the `wrapper-validation` action (if any) are added to the action definition, and that these are passed on to setup-gradle.
|
||||||
|
- Create and push a tag for the release.
|
||||||
|
- From CLI: `git tag v3.1.0 && git push --tags`
|
||||||
|
- Go to https://github.com/gradle/wrapper-validation-action/releases and "Draft new release"
|
||||||
|
- Use the newly created tag and copy the tag name exactly as the release title.
|
||||||
|
- In the release notes, point users to the gradle/actions release. Include a header informing users to switch to `gradle/actions/wrapper-validation`.
|
||||||
|
- Publish the release.
|
||||||
|
- Force push the `v3` tag (or current major version) to point to the new release.
|
||||||
|
- From CLI: `git tag -f -a -m "v3.0.0" v3 v3.0.0 && git push -f --tags`
|
||||||
|
|
||||||
|
## Post release steps
|
||||||
|
|
||||||
|
Submit PRs to update the GitHub starter workflow. Starter workflows contain content that should reference the Git hash of the current gradle/actions release:
|
||||||
|
https://github.com/actions/starter-workflows has [gradle](https://github.com/actions/starter-workflows/blob/main/ci/gradle.yml) and [gradle-publish](https://github.com/actions/starter-workflows/blob/main/ci/gradle-publish.yml): see [the v2.1.4 update PR](https://github.com/actions/starter-workflows/pull/1489) for an example.
|
||||||
|
|
||||||
|
Submit PRs to update the GitHub documentation. The documentation contains content that should reference the Git hash of the current gradle/actions release:
|
||||||
|
https://github.com/github/docs has [building-and-testing-java-with-gradle](https://github.com/github/docs/blob/main/content/actions/automating-builds-and-tests/building-and-testing-java-with-gradle.md) and [publishing-java-packages-with-gradle](https://github.com/github/docs/blob/main/content/actions/publishing-packages/publishing-java-packages-with-gradle.md) : see [the v2.1.4 update PR](https://github.com/github/docs/pull/16392) for an example.
|
||||||
|
|
||||||
11
actions.code-workspace
Normal file
11
actions.code-workspace
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
"folders": [
|
||||||
|
{
|
||||||
|
"path": "."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"path": "sources"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"settings": {}
|
||||||
|
}
|
||||||
35
build
Executable file
35
build
Executable file
@@ -0,0 +1,35 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
cd sources
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
all)
|
||||||
|
npm clean-install
|
||||||
|
npm run all
|
||||||
|
;;
|
||||||
|
act)
|
||||||
|
# Build and copy outputs to the dist directory
|
||||||
|
npm install
|
||||||
|
npm run build
|
||||||
|
cd ..
|
||||||
|
cp -r sources/dist .
|
||||||
|
# Run act
|
||||||
|
$@
|
||||||
|
# Revert the changes to the dist directory
|
||||||
|
git checkout -- dist
|
||||||
|
;;
|
||||||
|
init-scripts)
|
||||||
|
cd test/init-scripts
|
||||||
|
./gradlew check
|
||||||
|
;;
|
||||||
|
dist)
|
||||||
|
npm install
|
||||||
|
npm run build
|
||||||
|
cd ..
|
||||||
|
cp -r sources/dist .
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
npm install
|
||||||
|
npm run build
|
||||||
|
;;
|
||||||
|
esac
|
||||||
@@ -1,19 +1,6 @@
|
|||||||
# The `dependency-submission` action
|
## The `dependency-submission` action
|
||||||
|
|
||||||
The `gradle/actions/dependency-submission` action provides the simplest (and recommended) way to generate a
|
Generates and submits a dependency graph for a Gradle project, allowing GitHub to alert about reported vulnerabilities in your project dependencies.
|
||||||
dependency graph for your project. This action will attempt to detect all dependencies used by your build
|
|
||||||
without building and testing the project itself.
|
|
||||||
|
|
||||||
The dependency graph snapshot is generated via integration with the [GitHub Dependency Graph Gradle Plugin](https://plugins.gradle.org/plugin/org.gradle.github-dependency-graph-gradle-plugin), and submitted to your repository via the
|
|
||||||
[GitHub Dependency Submission API](https://docs.github.com/en/rest/dependency-graph/dependency-submission).
|
|
||||||
The generated snapshot files can be submitted in the same job, or saved for submission in a subsequent job.
|
|
||||||
|
|
||||||
The generated dependency graph includes all of the dependencies in your build, and is used by GitHub to generate
|
|
||||||
[Dependabot Alerts](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts)
|
|
||||||
for vulnerable dependencies, as well as to populate the
|
|
||||||
[Dependency Graph insights view](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/exploring-the-dependencies-of-a-repository#viewing-the-dependency-graph).
|
|
||||||
|
|
||||||
## General usage
|
|
||||||
|
|
||||||
The following workflow will generate a dependency graph for a Gradle project and submit it immediately to the repository via the
|
The following workflow will generate a dependency graph for a Gradle project and submit it immediately to the repository via the
|
||||||
Dependency Submission API. For most projects, this default configuration should be all that you need.
|
Dependency Submission API. For most projects, this default configuration should be all that you need.
|
||||||
@@ -23,388 +10,26 @@ Simply add this as a new workflow file to your repository (eg `.github/workflows
|
|||||||
```yaml
|
```yaml
|
||||||
name: Dependency Submission
|
name: Dependency Submission
|
||||||
|
|
||||||
on: [ push ]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
```
|
|
||||||
|
|
||||||
### Configuration parameters
|
|
||||||
|
|
||||||
In some cases, the default action configuration will not be sufficient, and additional action parameters will need to be specified.
|
|
||||||
|
|
||||||
See the example below for a summary, and the [Action Metadata file](action.yml) for a more detailed description of each input parameter.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Dependency Submission with advanced config
|
|
||||||
|
|
||||||
on: [ push ]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and save dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
with:
|
|
||||||
# Use a particular Gradle version instead of the configured wrapper.
|
|
||||||
gradle-version: 8.6
|
|
||||||
|
|
||||||
# The gradle project is not in the root of the repository.
|
|
||||||
build-root-directory: my-gradle-project
|
|
||||||
|
|
||||||
# Enable configuration-cache reuse for this build.
|
|
||||||
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
|
||||||
|
|
||||||
# Do not attempt to submit the dependency-graph. Save it as a workflow artifact.
|
|
||||||
dependency-graph: generate-and-upload
|
|
||||||
```
|
|
||||||
|
|
||||||
# Resolving a dependency vulnerability
|
|
||||||
|
|
||||||
## Finding the source of a dependency vulnerability
|
|
||||||
|
|
||||||
Once you have submitted a dependency graph, you may receive Dependabot Alerts warning about vulnerabilities in
|
|
||||||
dependencies of your project. In the case of transitive dependencies, it may not be obvious how that dependency is
|
|
||||||
used or what you can do to address the vulnerability alert.
|
|
||||||
|
|
||||||
The first step to investigating a Dependabot Alert is to determine the source of the dependency. One of the best ways to
|
|
||||||
do so is with a free Develocity Build Scan®, which makes it easy to explore the dependencies resolved in your build.
|
|
||||||
|
|
||||||
<img width="1069" alt="image" src="https://github.com/gradle/actions/assets/179734/3a637dfd-396c-4e94-8332-dcc6eb5a35ac">
|
|
||||||
|
|
||||||
In this example, we are searching for dependencies matching the name 'com.squareup.okio:okio' in the _Build Dependencies_ of
|
|
||||||
the project. You can easily see that this dependency originates from 'com.github.ben-manes:gradle-versions-plugin'.
|
|
||||||
Knowing the source of the dependency can help determine how to deal with the Dependabot Alert.
|
|
||||||
|
|
||||||
Note that you may need to look at both the _Dependencies_ and the _Build Dependencies_ of your project to find the
|
|
||||||
offending dependency.
|
|
||||||
|
|
||||||
### Publishing a Develocity Build Scan® from your dependency submission workflow
|
|
||||||
|
|
||||||
You can automatically publish a Build Scan on every run of `gradle/actions/dependency-submission`. Three input parameters are
|
|
||||||
required, one to enable publishing and two more to accept the [Develocity terms of service](https://gradle.com/terms-of-service).
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
- name: Generate and submit dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
with:
|
|
||||||
build-scan-publish: true
|
|
||||||
build-scan-terms-of-service-url: "https://gradle.com/terms-of-service"
|
|
||||||
build-scan-terms-of-service-agree: "yes"
|
|
||||||
```
|
|
||||||
|
|
||||||
### When you cannot publish a Build Scan®
|
|
||||||
|
|
||||||
If publishing a free Build Scan to https://scans.gradle.com isn't an option, and you don't have access to a private [Develocity
|
|
||||||
server](https://gradle.com/) for your project, you can obtain information about the each resolved dependency by running the `dependency-submission` workflow with debug logging enabled.
|
|
||||||
|
|
||||||
The simplest way to do so is to re-run the dependency-submission job with debug logging enabled:
|
|
||||||
|
|
||||||
<img width="665" alt="image" src="https://github.com/gradle/actions/assets/179734/d95b889a-09fb-4731-91f2-baebbf647e31">
|
|
||||||
|
|
||||||
When you do so, the Gradle build that generates the dependency-graph will include a log message for each dependency version included in the graph.
|
|
||||||
Given the details in one log message, you can run (locally) the built-in [dependencyInsight](https://docs.gradle.org/current/userguide/viewing_debugging_dependencies.html#dependency_insights) task
|
|
||||||
to determine exactly how the dependency was resolved.
|
|
||||||
|
|
||||||
For example, given the following message in the logs:
|
|
||||||
```
|
|
||||||
Detected dependency 'com.google.guava:guava:32.1.3-jre': project = ':my-subproject', configuration = 'compileClasspath'
|
|
||||||
```
|
|
||||||
|
|
||||||
You would run the following command locally:
|
|
||||||
```
|
|
||||||
./gradlew :my-subproject:dependencyInsight --configuration compileClasspath --dependency com.google.guava:guava:32.1.3-jre
|
|
||||||
```
|
|
||||||
|
|
||||||
#### Dealing with 'classpath' configuration
|
|
||||||
|
|
||||||
If the configuration value in the log message is "classpath" then instead of running `dependency-insight` you'll need to run the Gradle
|
|
||||||
`buildEnvironment` task.
|
|
||||||
|
|
||||||
For example, given the following message in the logs:
|
|
||||||
```
|
|
||||||
Detected dependency 'xerces:xercesImpl:2.12.2': project = ':my-subproject', configuration = 'classpath'
|
|
||||||
```
|
|
||||||
|
|
||||||
You would run the following command locally to expose the `xercesImpl` dependency:
|
|
||||||
```
|
|
||||||
./gradlew :my-subproject:buildEnvironment | grep -C 5 xercesImpl
|
|
||||||
```
|
|
||||||
|
|
||||||
## Updating the dependency version
|
|
||||||
|
|
||||||
Once you've discovered the source of the dependency, the most obvious fix is to update the dependency to a patched version that does not
|
|
||||||
suffer the vulnerability. For direct dependencies, this is often straightforward. But for transitive dependencies it can be tricky.
|
|
||||||
|
|
||||||
### Dependency source is specified directly in the build
|
|
||||||
|
|
||||||
If the dependency is used to compile your code or run your tests, it's normal for the underlying "source" of the dependency to have a
|
|
||||||
version configured directly in the build. For example, if you have a vulnerable version of `com.squareup.okio:okio` in your `compileClasspath`, then
|
|
||||||
it's likely you have a dependency like `com.squareup.moshi:moshi` configured as an `api` or `implementation` dependency.
|
|
||||||
|
|
||||||
In this case there are 2 possibilities:
|
|
||||||
1. There is a newer, compatible version of `com.squareup.moshi:moshi` available, and you can just bump the version number.
|
|
||||||
2. There isn't a newer, compatible version of `com.squareup.moshi:moshi`
|
|
||||||
|
|
||||||
In the second case, you can add a Dependency Constraint, to force the use of the newest version of `com.squareup.okio`:
|
|
||||||
|
|
||||||
```kotlin
|
|
||||||
dependencies {
|
|
||||||
implementation("com.squareup.moshi:moshi:1.12.0")
|
|
||||||
constraints {
|
|
||||||
// Force a newer version of okio in transitive resolution
|
|
||||||
implementation("com.squareup.okio:okio:3.6.0")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Dependency source is a plugin classpath
|
|
||||||
|
|
||||||
If the vulnerable dependency is introduced by a Gradle plugin, again the best option is to look for a newer version of the plugin.
|
|
||||||
But if none is available, you can still use a dependency constraint to force a newer transitive version to be used.
|
|
||||||
|
|
||||||
The dependency constraint must be added to the `classpath` configuration of the buildscript that loads the plugin.
|
|
||||||
|
|
||||||
```kotlin
|
|
||||||
buildscript {
|
|
||||||
repositories {
|
|
||||||
gradlePluginPortal()
|
|
||||||
}
|
|
||||||
dependencies {
|
|
||||||
constraints {
|
|
||||||
// Force a newer version of okio in transitive resolution
|
|
||||||
classpath("com.squareup.okio:okio:3.6.0")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
plugins {
|
|
||||||
id("com.github.ben-manes.versions") version("0.51.0")
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
## Limiting the dependencies that appear in the dependency graph
|
|
||||||
|
|
||||||
By default, the `dependency-submission` action attempts to detect all dependencies declared and used by your Gradle build.
|
|
||||||
At times it may helpful to limit the dependencies reported to GitHub, to avoid security alerts for dependencies that
|
|
||||||
don't form a critical part of your product. For example, a vulnerability in the tool you use to generate documentation
|
|
||||||
may not be as important as a vulnerability in one of your runtime dependencies.
|
|
||||||
|
|
||||||
The `dependency-submission` action provides a convenient mechanism to filter the projects and configurations that
|
|
||||||
contribute to the dependency graph.
|
|
||||||
|
|
||||||
> [!NOTE]
|
|
||||||
> Ideally, all dependencies involved in building and testing a project will be extracted and reported in a dependency graph.
|
|
||||||
> These dependencies would be assigned to different scopes (eg development, runtime, testing) and the GitHub UI would make it easy to opt-in to security alerts for different dependency scopes.
|
|
||||||
> However, this functionality does not yet exist.
|
|
||||||
|
|
||||||
### Excluding certain Gradle projects from to the dependency graph
|
|
||||||
|
|
||||||
If you do not want the dependency graph to include dependencies from every project in your build,
|
|
||||||
you can easily exclude certain projects from the dependency extraction process.
|
|
||||||
|
|
||||||
To restrict which Gradle subprojects contribute to the report, specify which projects to exclude via a regular expression.
|
|
||||||
You can provide this value via the `DEPENDENCY_GRAPH_EXCLUDE_PROJECTS` environment variable or system property.
|
|
||||||
|
|
||||||
Note that excluding a project in this way only removes dependencies that are _resolved_ as part of that project, and may
|
|
||||||
not necessarily remove all dependencies _declared_ in that project. If another project depends on the excluded project
|
|
||||||
then it may transitively resolve dependencies declared in the excluded project: these dependencies will still be included
|
|
||||||
in the generated dependency graph.
|
|
||||||
|
|
||||||
### Excluding certain Gradle configurations from to the dependency graph
|
|
||||||
|
|
||||||
Similarly to Gradle projects, it is possible to exclude a set of configuration instances from dependency graph generation,
|
|
||||||
so that dependencies resolved by those configurations are not included.
|
|
||||||
|
|
||||||
To restrict which Gradle configurations contribute to the report, specify which configurations to exclude via a regular expression.
|
|
||||||
You can provide this value via the `DEPENDENCY_GRAPH_EXCLUDE_CONFIGURATIONS` environment variable or system property.
|
|
||||||
|
|
||||||
Note that configuration exclusion applies to the configuration in which the dependency is _resolved_ which is not necessarily
|
|
||||||
the configuration where the dependency is _declared_. For example if you decare a dependency as `implementation` in
|
|
||||||
a Java project, that dependency will be resolved in `compileClasspath`, `runtimeClasspath` and possibly other configurations.
|
|
||||||
|
|
||||||
### Example of project and configuration filtering
|
|
||||||
|
|
||||||
For example, if you want to exclude dependencies in the `buildSrc` project, and exclude dependencies from the `testCompileClasspath` and `testRuntimeClasspath` configurations, you would use the following configuration:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
env:
|
|
||||||
# Exclude all dependencies that originate solely in the 'buildSrc' project
|
|
||||||
DEPENDENCY_GRAPH_EXCLUDE_PROJECTS: ':buildSrc'
|
|
||||||
# Exclude dependencies that are only resolved in test classpaths
|
|
||||||
DEPENDENCY_GRAPH_EXCLUDE_CONFIGURATIONS: '.*[Tt]est(Compile|Runtime)Classpath'
|
|
||||||
```
|
|
||||||
|
|
||||||
### Other filtering options
|
|
||||||
|
|
||||||
The [GitHub Dependency Graph Gradle Plugin](https://plugins.gradle.org/plugin/org.gradle.github-dependency-graph-gradle-plugin)
|
|
||||||
has other filtering options that may be useful.
|
|
||||||
See [the docs](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#filtering-which-gradle-configurations-contribute-to-the-dependency-graph) for details.
|
|
||||||
|
|
||||||
# Advance usage scenarios
|
|
||||||
|
|
||||||
## Using a custom plugin repository
|
|
||||||
|
|
||||||
By default, the action downloads the `github-dependency-graph-gradle-plugin` from the Gradle Plugin Portal (https://plugins.gradle.org). If your GitHub Actions environment does not have access to this URL, you can specify a custom plugin repository to use.
|
|
||||||
Do so by setting the `GRADLE_PLUGIN_REPOSITORY_URL` environment variable.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
env:
|
|
||||||
GRADLE_PLUGIN_REPOSITORY_URL: "https://gradle-plugins-proxy.mycorp.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
## Integrating the `dependency-review-action`
|
|
||||||
|
|
||||||
The GitHub [dependency-review-action](https://github.com/actions/dependency-review-action) helps you
|
|
||||||
understand dependency changes (and the security impact of these changes) for a pull request,
|
|
||||||
by comparing the dependency graph for the pull-request with that of the HEAD commit.
|
|
||||||
|
|
||||||
Example of a pull request workflow that executes a build for a pull request and runs the `dependency-review-action`:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Dependency review for pull requests
|
|
||||||
|
|
||||||
on: [ pull_request ]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and submit dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
|
|
||||||
dependency-review:
|
|
||||||
needs: dependency-submission
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Perform dependency review
|
|
||||||
uses: actions/dependency-review-action@v3
|
|
||||||
```
|
|
||||||
|
|
||||||
Note that the `dependency-submission` action submits the dependency graph at the completion of the workflow Job.
|
|
||||||
For this reason, the `dependency-review-action` must be executed in a dependent job, and not as a subsequent step in the job that generates the dependency graph.
|
|
||||||
|
|
||||||
## Usage with pull requests from public forked repositories
|
|
||||||
|
|
||||||
This `contents: write` permission is [not available for any workflow that is triggered by a pull request submitted from a public forked repository](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token).
|
|
||||||
This limitation is designed to prevent a malicious pull request from effecting repository changes.
|
|
||||||
|
|
||||||
Because of this restriction, we require 2 separate workflows in order to generate and submit a dependency graph:
|
|
||||||
1. The first workflow runs directly against the pull request sources and will `generate-and-upload` the dependency graph.
|
|
||||||
2. The second workflow is triggered on `workflow_run` of the first workflow, and will `download-and-submit` the previously saved dependency graph.
|
|
||||||
|
|
||||||
***Main workflow file***
|
|
||||||
```yaml
|
|
||||||
name: Generate and save dependency graph
|
|
||||||
|
|
||||||
on: [ pull_request ]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read # 'write' permission is not available
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-submission:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Generate and save dependency graph
|
|
||||||
uses: gradle/actions/dependency-submission@v3
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-upload
|
|
||||||
```
|
|
||||||
|
|
||||||
***Dependent workflow file***
|
|
||||||
```yaml
|
|
||||||
name: Download and submit dependency graph
|
|
||||||
|
|
||||||
on:
|
on:
|
||||||
workflow_run:
|
push:
|
||||||
workflows: ['Generate and save dependency graph']
|
branches: ['main']
|
||||||
types: [completed]
|
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
submit-dependency-graph:
|
dependency-submission:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Download and submit dependency graph
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: 'temurin'
|
||||||
|
java-version: 17
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
uses: gradle/actions/dependency-submission@v3
|
uses: gradle/actions/dependency-submission@v3
|
||||||
with:
|
|
||||||
dependency-graph: download-and-submit # Download saved dependency-graph and submit
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Integrating `dependency-review-action` for pull requests from public forked repositories
|
See the [full action documentation](../docs/dependency-submission.md) for more advanced usage scenarios.
|
||||||
|
|
||||||
To integrate the `dependency-review-action` into the pull request workflows above, a third workflow file is required.
|
|
||||||
This workflow will be triggered directly on `pull_request`, but will wait until the dependency graph results are
|
|
||||||
submitted before the dependency review can complete. The period to wait is controlled by the `retry-on-snapshot-warnings` input parameters.
|
|
||||||
|
|
||||||
Here's an example of a separate "Dependency Review" workflow that will wait for 10 minutes for the above PR check workflow to complete.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: dependency-review
|
|
||||||
|
|
||||||
on: [ pull_request ]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
dependency-review:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: 'Dependency Review'
|
|
||||||
uses: actions/dependency-review-action@v3
|
|
||||||
with:
|
|
||||||
retry-on-snapshot-warnings: true
|
|
||||||
retry-on-snapshot-warnings-timeout: 600
|
|
||||||
```
|
|
||||||
|
|
||||||
The `retry-on-snapshot-warnings-timeout` (in seconds) needs to be long enough to allow the entire `Generate and save dependency graph` and `Download and submit dependency graph` workflows (above) to complete.
|
|
||||||
|
|
||||||
# Gradle version compatibility
|
|
||||||
|
|
||||||
Dependency-graph generation is compatible with most versions of Gradle >= `5.2`, and is tested regularly against
|
|
||||||
Gradle versions `5.2.1`, `5.6.4`, `6.0.1`, `6.9.4`, `7.1.1` and `7.6.3`, as well as all patched versions of Gradle 8.x.
|
|
||||||
|
|
||||||
A known exception to this is that Gradle `7.0`, `7.0.1` and `7.0.2` are not supported.
|
|
||||||
|
|
||||||
See [here](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#gradle-compatibility) for complete compatibility information.
|
|
||||||
|
|||||||
@@ -2,20 +2,97 @@ name: Gradle Dependency Submission
|
|||||||
description: Generates a dependency graph for a Gradle project and submits it via the Dependency Submission API
|
description: Generates a dependency graph for a Gradle project and submits it via the Dependency Submission API
|
||||||
|
|
||||||
inputs:
|
inputs:
|
||||||
|
# Gradle execution configuration
|
||||||
gradle-version:
|
gradle-version:
|
||||||
description: |
|
description: |
|
||||||
Gradle version to use. If specified, this Gradle version will be downloaded, added to the PATH and used for invoking Gradle.
|
Gradle version to use. If specified, this Gradle version will be downloaded, added to the PATH and used for invoking Gradle.
|
||||||
If not provided, it is assumed that the project uses the Gradle Wrapper.
|
If not provided, it is assumed that the project uses the Gradle Wrapper.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
build-root-directory:
|
build-root-directory:
|
||||||
description: Path to the root directory of the build. Default is the root of the GitHub workspace.
|
description: Path to the root directory of the build. Default is the root of the GitHub workspace.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
dependency-resolution-task:
|
||||||
|
description: |
|
||||||
|
Task(s) that should be executed in order to resolve all project dependencies.
|
||||||
|
By default, the built-in `:ForceDependencyResolutionPlugin_resolveAllDependencies` task is executed.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
additional-arguments:
|
||||||
|
description: |
|
||||||
|
Additional arguments to pass to Gradle when generating the dependency graph.
|
||||||
|
For example, `--no-configuration-cache --stacktrace`.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
# Cache configuration
|
||||||
|
cache-disabled:
|
||||||
|
description: When 'true', all caching is disabled. No entries will be written to or read from the cache.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
cache-read-only:
|
||||||
|
description: |
|
||||||
|
When 'true', existing entries will be read from the cache but no entries will be written.
|
||||||
|
By default this value is 'false' for workflows on the GitHub default branch and 'true' for workflows on other branches.
|
||||||
|
required: false
|
||||||
|
default: ${{ github.event.repository != null && github.ref_name != github.event.repository.default_branch }}
|
||||||
|
|
||||||
|
cache-write-only:
|
||||||
|
description: |
|
||||||
|
When 'true', entries will not be restored from the cache but will be saved at the end of the Job.
|
||||||
|
Setting this to 'true' implies cache-read-only will be 'false'.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
cache-overwrite-existing:
|
||||||
|
description: When 'true', a pre-existing Gradle User Home will not prevent the cache from being restored.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
cache-encryption-key:
|
cache-encryption-key:
|
||||||
description: |
|
description: |
|
||||||
A base64 encoded AES key used to encrypt the configuration-cache data. The key is exported as 'GRADLE_ENCRYPTION_KEY' for later steps.
|
A base64 encoded AES key used to encrypt the configuration-cache data. The key is exported as 'GRADLE_ENCRYPTION_KEY' for later steps.
|
||||||
A suitable key can be generated with `openssl rand -base64 16`.
|
A suitable key can be generated with `openssl rand -base64 16`.
|
||||||
Configuration-cache data will not be saved/restored without an encryption key being provided.
|
Configuration-cache data will not be saved/restored without an encryption key being provided.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
cache-cleanup:
|
||||||
|
description: |
|
||||||
|
Specifies if the action should attempt to remove any stale/unused entries from the Gradle User Home prior to saving to the GitHub Actions cache.
|
||||||
|
By default, no cleanup is performed. It can be configured to run every time, or only when all Gradle builds succeed for the Job.
|
||||||
|
Valid values are 'never', 'on-success' and 'always'.
|
||||||
|
required: false
|
||||||
|
default: 'on-success'
|
||||||
|
|
||||||
|
gradle-home-cache-cleanup:
|
||||||
|
description: When 'true', the action will attempt to remove any stale/unused entries from the Gradle User Home prior to saving to the GitHub Actions cache.
|
||||||
|
required: false
|
||||||
|
deprecation-message: This input has been superceded by the 'cache-cleanup' input parameter.
|
||||||
|
|
||||||
|
gradle-home-cache-includes:
|
||||||
|
description: Paths within Gradle User Home to cache.
|
||||||
|
required: false
|
||||||
|
default: |
|
||||||
|
caches
|
||||||
|
notifications
|
||||||
|
|
||||||
|
gradle-home-cache-excludes:
|
||||||
|
description: Paths within Gradle User Home to exclude from cache.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
# Job summary configuration
|
||||||
|
add-job-summary:
|
||||||
|
description: Specifies when a Job Summary should be inluded in the action results. Valid values are 'never', 'always' (default), and 'on-failure'.
|
||||||
|
required: false
|
||||||
|
default: 'always'
|
||||||
|
|
||||||
|
add-job-summary-as-pr-comment:
|
||||||
|
description: Specifies when each Job Summary should be added as a PR comment. Valid values are 'never' (default), 'always', and 'on-failure'. No action will be taken if the workflow was not triggered from a pull request.
|
||||||
|
required: false
|
||||||
|
default: 'never'
|
||||||
|
|
||||||
|
# Dependency Graph configuration
|
||||||
dependency-graph:
|
dependency-graph:
|
||||||
description: |
|
description: |
|
||||||
Specifies how the dependency-graph should be handled by this action. By default a dependency-graph will be generated and submitted.
|
Specifies how the dependency-graph should be handled by this action. By default a dependency-graph will be generated and submitted.
|
||||||
@@ -29,57 +106,123 @@ inputs:
|
|||||||
required to submit via the Dependency Submission API.
|
required to submit via the Dependency Submission API.
|
||||||
required: false
|
required: false
|
||||||
default: 'generate-and-submit'
|
default: 'generate-and-submit'
|
||||||
additional-arguments:
|
|
||||||
|
dependency-graph-report-dir:
|
||||||
description: |
|
description: |
|
||||||
Additional arguments to pass to Gradle. For example, `--no-configuration-cache --stacktrace`.
|
Specifies where the dependency graph report will be generated.
|
||||||
|
Paths can relative or absolute. Relative paths are resolved relative to the workspace directory.
|
||||||
|
required: false
|
||||||
|
default: 'dependency-graph-reports'
|
||||||
|
|
||||||
|
dependency-graph-continue-on-failure:
|
||||||
|
description: When 'false' a failure to generate or submit a dependency graph will fail the Step or Job. When 'true' a warning will be emitted but no failure will result.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
dependency-graph-exclude-projects:
|
||||||
|
description: |
|
||||||
|
Gradle projects that should be excluded from dependency graph (regular expression).
|
||||||
|
When set, any matching project will be excluded.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-include-projects:
|
||||||
|
description: |
|
||||||
|
Gradle projects that should be included in dependency graph (regular expression).
|
||||||
|
When set, only matching projects will be included.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-exclude-configurations:
|
||||||
|
description: |
|
||||||
|
Gradle configurations that should be included in dependency graph (regular expression).
|
||||||
|
When set, anymatching configurations will be excluded.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-include-configurations:
|
||||||
|
description: |
|
||||||
|
Gradle configurations that should be included in dependency graph (regular expression).
|
||||||
|
When set, only matching configurations will be included.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
artifact-retention-days:
|
||||||
|
description: Specifies the number of days to retain any artifacts generated by the action. If not set, the default retention settings for the repository will apply.
|
||||||
|
required: false
|
||||||
|
default: 1
|
||||||
|
|
||||||
|
# Build Scan configuration
|
||||||
build-scan-publish:
|
build-scan-publish:
|
||||||
description: |
|
description: |
|
||||||
Set to 'true' to automatically publish build results as a Build Scan on scans.gradle.com.
|
Set to 'true' to automatically publish build results as a Build Scan on scans.gradle.com.
|
||||||
For publication to succeed without user input, you must also provide values for `build-scan-terms-of-service-url` and 'build-scan-terms-of-service-agree'.
|
For publication to succeed without user input, you must also provide values for `build-scan-terms-of-use-url` and 'build-scan-terms-of-use-agree'.
|
||||||
required: false
|
required: false
|
||||||
default: false
|
default: false
|
||||||
build-scan-terms-of-service-url:
|
|
||||||
description: The URL to the Build Scan® terms of service. This input must be set to 'https://gradle.com/terms-of-service'.
|
build-scan-terms-of-use-url:
|
||||||
required: false
|
description: The URL to the Build Scan® terms of use. This input must be set to 'https://gradle.com/terms-of-service' or 'https://gradle.com/help/legal-terms-of-use'.
|
||||||
build-scan-terms-of-service-agree:
|
|
||||||
description: Indicate that you agree to the Build Scan® terms of service. This input value must be "yes".
|
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
build-scan-terms-of-use-agree:
|
||||||
|
description: Indicate that you agree to the Build Scan® terms of use. This input value must be "yes".
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-access-key:
|
||||||
|
description: Develocity access key. Should be set to a secret containing the Develocity Access key.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-token-expiry:
|
||||||
|
description: The Develocity short-lived access tokens expiry in hours. Default is 2 hours.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
# Wrapper validation configuration
|
||||||
|
validate-wrappers:
|
||||||
|
description: |
|
||||||
|
When 'true' the action will automatically validate all wrapper jars found in the repository.
|
||||||
|
If the wrapper checksums are not valid, the action will fail.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
allow-snapshot-wrappers:
|
||||||
|
description: |
|
||||||
|
When 'true', wrapper validation will include the checksums of snapshot wrapper jars.
|
||||||
|
Use this if you are running with nightly or snapshot versions of the Gradle wrapper.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
# DEPRECATED ACTION INPUTS
|
||||||
|
|
||||||
|
# EXPERIMENTAL ACTION INPUTS
|
||||||
|
# The following action properties allow fine-grained tweaking of the action caching behaviour.
|
||||||
|
# These properties are experimental and not (yet) designed for production use, and may change without notice in a subsequent release of `setup-gradle`.
|
||||||
|
# Use at your own risk!
|
||||||
|
gradle-home-cache-strict-match:
|
||||||
|
description: When 'true', the action will not attempt to restore the Gradle User Home entries from other Jobs.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
|
# INTERNAL ACTION INPUTS
|
||||||
|
# These inputs should not be configured directly, and are only used to pass environmental information to the action
|
||||||
|
workflow-job-context:
|
||||||
|
description: Used to uniquely identify the current job invocation. Defaults to the matrix values for this job; this should not be overridden by users (INTERNAL).
|
||||||
|
required: false
|
||||||
|
default: ${{ toJSON(matrix) }}
|
||||||
|
|
||||||
|
github-token:
|
||||||
|
description: The GitHub token used to authenticate when submitting via the Dependency Submission API.
|
||||||
|
default: ${{ github.token }}
|
||||||
|
required: false
|
||||||
|
|
||||||
|
outputs:
|
||||||
|
build-scan-url:
|
||||||
|
description: Link to the Build Scan® generated by a Gradle build. Note that this output applies to a Step executing Gradle, not to the `setup-gradle` Step itself.
|
||||||
|
dependency-graph-file:
|
||||||
|
description: Path to the GitHub Dependency Graph snapshot file generated by a Gradle build. Note that this output applies to a Step executing Gradle, not to the `setup-gradle` Step itself.
|
||||||
|
gradle-version:
|
||||||
|
description: Version of Gradle that was setup by the action
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: "composite"
|
using: 'node20'
|
||||||
steps:
|
main: '../dist/dependency-submission/main/index.js'
|
||||||
- name: Check no setup-gradle
|
post: '../dist/dependency-submission/post/index.js'
|
||||||
shell: bash
|
|
||||||
run: |
|
branding:
|
||||||
if [ -n "${GRADLE_BUILD_ACTION_SETUP_COMPLETED}" ]; then
|
icon: 'box'
|
||||||
echo "The dependency-submission action cannot be used in the same Job as the setup-gradle action. Please use a separate Job for dependency submission."
|
color: 'gray-dark'
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
- name: Generate dependency graph
|
|
||||||
if: ${{ inputs.dependency-graph == 'generate-and-submit' || inputs.dependency-graph == 'generate-and-upload' }}
|
|
||||||
uses: gradle/actions/setup-gradle@v3.1.0
|
|
||||||
with:
|
|
||||||
dependency-graph: ${{ inputs.dependency-graph }}
|
|
||||||
dependency-graph-continue-on-failure: false
|
|
||||||
gradle-version: ${{ inputs.gradle-version }}
|
|
||||||
build-root-directory: ${{ inputs.build-root-directory }}
|
|
||||||
cache-encryption-key: ${{ inputs.cache-encryption-key }}
|
|
||||||
build-scan-publish: ${{ inputs.build-scan-publish }}
|
|
||||||
build-scan-terms-of-service-url: ${{ inputs.build-scan-terms-of-service-url }}
|
|
||||||
build-scan-terms-of-service-agree: ${{ inputs.build-scan-terms-of-service-agree }}
|
|
||||||
artifact-retention-days: 1
|
|
||||||
arguments: |
|
|
||||||
-Dorg.gradle.configureondemand=false
|
|
||||||
-Dorg.gradle.dependency.verification=off
|
|
||||||
-Dorg.gradle.unsafe.isolated-projects=false
|
|
||||||
:ForceDependencyResolutionPlugin_resolveAllDependencies
|
|
||||||
${{ inputs.additional-arguments }}
|
|
||||||
- name: Download and submit dependency graph
|
|
||||||
if: ${{ inputs.dependency-graph == 'download-and-submit' }}
|
|
||||||
uses: gradle/actions/setup-gradle@v3.1.0
|
|
||||||
with:
|
|
||||||
dependency-graph: download-and-submit
|
|
||||||
dependency-graph-continue-on-failure: false
|
|
||||||
cache-disabled: true
|
|
||||||
|
|||||||
166878
dist/dependency-submission/main/index.js
vendored
Normal file
166878
dist/dependency-submission/main/index.js
vendored
Normal file
File diff suppressed because one or more lines are too long
1
dist/dependency-submission/main/index.js.map
vendored
Normal file
1
dist/dependency-submission/main/index.js.map
vendored
Normal file
File diff suppressed because one or more lines are too long
120433
dist/dependency-submission/post/index.js
vendored
Normal file
120433
dist/dependency-submission/post/index.js
vendored
Normal file
File diff suppressed because one or more lines are too long
1
dist/dependency-submission/post/index.js.map
vendored
Normal file
1
dist/dependency-submission/post/index.js.map
vendored
Normal file
File diff suppressed because one or more lines are too long
33196
dist/setup-gradle/main/index.js
vendored
33196
dist/setup-gradle/main/index.js
vendored
File diff suppressed because one or more lines are too long
2
dist/setup-gradle/main/index.js.map
vendored
2
dist/setup-gradle/main/index.js.map
vendored
File diff suppressed because one or more lines are too long
35600
dist/setup-gradle/post/index.js
vendored
35600
dist/setup-gradle/post/index.js
vendored
File diff suppressed because one or more lines are too long
2
dist/setup-gradle/post/index.js.map
vendored
2
dist/setup-gradle/post/index.js.map
vendored
File diff suppressed because one or more lines are too long
110674
dist/wrapper-validation/main/index.js
vendored
Normal file
110674
dist/wrapper-validation/main/index.js
vendored
Normal file
File diff suppressed because one or more lines are too long
1
dist/wrapper-validation/main/index.js.map
vendored
Normal file
1
dist/wrapper-validation/main/index.js.map
vendored
Normal file
File diff suppressed because one or more lines are too long
58
docs/dependency-submission-faq.md
Normal file
58
docs/dependency-submission-faq.md
Normal file
@@ -0,0 +1,58 @@
|
|||||||
|
# Dependency submission FAQ
|
||||||
|
|
||||||
|
Implementing a `dependency-submission` workflow for your repository is documented in the
|
||||||
|
[core documentation](dependency-submission.md).
|
||||||
|
But getting it working is the easy part: the dependency alerts you recieve can be confusing and surprising.
|
||||||
|
Here are some common questions answered.
|
||||||
|
|
||||||
|
### How can I easily try this out without experimenting on my main repository?
|
||||||
|
The https://github.com/gradle/github-dependency-submission-demo repository is setup as a tutorial for you to fork and play with.
|
||||||
|
|
||||||
|
### How can I tell if the `dependency-submission` action is working?
|
||||||
|
Inspect the Dependency Graph for your project (Insights -> Dependency Graph). You should see some dependencies annotated with "Detected by GitHub Dependency Graph Gradle Plugin"
|
||||||
|
|
||||||
|
### Why is `(Maven)` stated for all dependencies submitted by this action? I'm not using Maven.
|
||||||
|
This simply indicates that the dependency was resolved from a standard Gradle/Maven artifact repository. It does not imply which build tool is used.
|
||||||
|
|
||||||
|
### Why is every dependency attributed to `settings.gradle.kts`?
|
||||||
|
All dependendies detected by the `dependency-submission` action are attributed to the Gradle project as a whole. We found that the best way is to link to the project `Settings` file.
|
||||||
|
We do not currently attempt to attribute dependencies to the actual file where they were declared.
|
||||||
|
|
||||||
|
### Why aren't dependencies be linked to the source file where they are declared?
|
||||||
|
There are a couple of reasons for this:
|
||||||
|
1. Gradle doesn't currently provide a mechanism to determine the location where a dependency is declared. In fact, the resulting dependency version can be influenced by many different sources within a Gradle project.
|
||||||
|
2. The GitHub Dependency Graph was modelled heavily on NPM and doesn't really map well to having multiple source locations for a single dependency declaration.
|
||||||
|
|
||||||
|
We have long-term plans to improve the first point, and we are working with GitHub to resolve the second. However, at this stage the behaviour your are experiencing is what is expected.
|
||||||
|
|
||||||
|
### My repository dependency graph contains a dependency that isn't anywhere in my build. Why is the `dependency-submission` action reporting dependencies I'm not using?
|
||||||
|
If you see a particular dependency version reported in the dependency graph, it means your build is resolving that dependency at some point.
|
||||||
|
You may be surprised what transitive dependencies are brought in by declared dependencies and applied plugins in your build.
|
||||||
|
[See here for a HOW-TO](dependency-submission.md#resolving-a-dependency-vulnerability) on getting the bottom of why the dependency is being resolved.
|
||||||
|
|
||||||
|
### I see multiple versions of the same dependency in the dependency graph, but I'm only declaring a single version in my build. Why is the action reporting dependency versions I'm not using?
|
||||||
|
This is almost certainly because the dependency in question is actually being resolved with different versions in different dependency configurations.
|
||||||
|
For example, you may have one version brought in as a plugin dependency (resolved in the `classpath` configuration) and another used directly as a code dependency (resolved in the `compileClasspath` configuration).
|
||||||
|
[See here for a HOW-TO](dependency-submission.md#resolving-a-dependency-vulnerability) on getting the bottom of why the dependency is being resolved.
|
||||||
|
By far the easiest way is to publish a Build Scan® for the workflow run: [this is easily achieved with some additional action configuration](dependency-submission.md#publishing-a-develocity-build-scan-from-your-dependency-submission-workflow).
|
||||||
|
|
||||||
|
### I'm not seeing any security vulnerabilities for any of my dependencies. How can I be sure this is working?
|
||||||
|
First check that [Dependabot Alerts](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts) are enabled for your repository.
|
||||||
|
Without this, your dependency graph may be populated but you won't see which dependencies are potentially vulnerable.
|
||||||
|
|
||||||
|
### How can I use Dependabot Security Updates to generate a PR to update my vulnerable dependencies?
|
||||||
|
In most cases, the Dependabot Security Updates feature is not able to automatically generate a PR to update a dependency version.
|
||||||
|
This can be due to the vulnerable dependency being transitive, or because the Dependabot implementation doesn't understand how to update the dependency version.
|
||||||
|
In a few select cases the Dependabot security update will work and successfully generate a pull-request. For example when a direct dependency version is listed in a TOML dependency catalog.
|
||||||
|
|
||||||
|
### I'm getting many false positive Dependabot Alerts for dependencies that aren't used by my project. Why are these dependencies being reported?
|
||||||
|
The `dependency-submission` action resolves all of the dependencies in your build. This includes plugins, dependencies you've declared, test dependencies, and all transitive dependencies of these.
|
||||||
|
It doesn't matter how the dependencies are declared: the ones being resolved by Gradle are the ones being reported.
|
||||||
|
|
||||||
|
Many people are surprised to see what dependencies are actually being resolved when they run their builds, but I'm yet to see a case where the dependencies being reported are actually incorrect.
|
||||||
|
|
||||||
|
Please [follow the instructions here](dependency-submission.md#finding-the-source-of-a-dependency-vulnerability) to identify the source of the dependency version that is being reported.
|
||||||
|
|
||||||
|
Once you have worked out why it is being resolved, you can either [update the dependency version](dependency-submission.md#updating-the-dependency-version)
|
||||||
|
or [exclude it from the submitted dependency graph](dependency-submission.md#limiting-the-dependencies-that-appear-in-the-dependency-graph).
|
||||||
|
|
||||||
428
docs/dependency-submission.md
Normal file
428
docs/dependency-submission.md
Normal file
@@ -0,0 +1,428 @@
|
|||||||
|
# The `dependency-submission` action
|
||||||
|
|
||||||
|
The `gradle/actions/dependency-submission` action provides the simplest (and recommended) way to generate a
|
||||||
|
dependency graph for your project. This action will attempt to detect all dependencies used by your build
|
||||||
|
without building and testing the project itself.
|
||||||
|
|
||||||
|
The dependency graph snapshot is generated via integration with the [GitHub Dependency Graph Gradle Plugin](https://plugins.gradle.org/plugin/org.gradle.github-dependency-graph-gradle-plugin), and submitted to your repository via the
|
||||||
|
[GitHub Dependency Submission API](https://docs.github.com/en/rest/dependency-graph/dependency-submission).
|
||||||
|
The generated snapshot files can be submitted in the same job, or saved for submission in a subsequent job.
|
||||||
|
|
||||||
|
The generated dependency graph includes all of the dependencies in your build, and is used by GitHub to generate
|
||||||
|
[Dependabot Alerts](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts)
|
||||||
|
for vulnerable dependencies, as well as to populate the
|
||||||
|
[Dependency Graph insights view](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/exploring-the-dependencies-of-a-repository#viewing-the-dependency-graph).
|
||||||
|
|
||||||
|
If you're confused by the behaviour you're seeing or have specific questions, please check out [the FAQ](dependency-submission-faq.md) before raising an issue.
|
||||||
|
|
||||||
|
## General usage
|
||||||
|
|
||||||
|
The following workflow will generate a dependency graph for a Gradle project and submit it immediately to the repository via the
|
||||||
|
Dependency Submission API. For most projects, this default configuration should be all that you need.
|
||||||
|
|
||||||
|
Simply add this as a new workflow file to your repository (eg `.github/workflows/dependency-submission.yml`).
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: Dependency Submission
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ 'main' ]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-submission:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
### Gradle execution
|
||||||
|
|
||||||
|
To generate a dependency graph, the `dependency-submission` action must perform a Gradle execution that resolves
|
||||||
|
the dependencies of the project. All dependencies that are resolved in this execution will be included in the
|
||||||
|
generated dependency graph. By default action executes a built-in task that is designed to resolve all build dependencies
|
||||||
|
(`:ForceDependencyResolutionPlugin_resolveAllDependencies`).
|
||||||
|
|
||||||
|
The action looks for a Gradle project in the root of the workspace, and executes this project with
|
||||||
|
the Gradle wrapper, if configured for the project. If the wrapper is not configured, whatever `gradle` available
|
||||||
|
on the command-line will be used.
|
||||||
|
|
||||||
|
The action provides the ability to override the Gradle version and task to execute, as well as provide
|
||||||
|
additional arguments that will be passed to Gradle on the command-line. See [Configuration Parameters](#configuration-parameters) below.
|
||||||
|
|
||||||
|
### Publishing a Develocity Build Scan® from your dependency submission workflow
|
||||||
|
|
||||||
|
You can automatically publish a free Develocity Build Scan on every run of `gradle/actions/dependency-submission`.
|
||||||
|
Three input parameters are required, one to enable publishing and two more to accept the
|
||||||
|
[Develocity terms of use](https://gradle.com/help/legal-terms-of-use).
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
with:
|
||||||
|
build-scan-publish: true
|
||||||
|
build-scan-terms-of-use-url: "https://gradle.com/help/legal-terms-of-use"
|
||||||
|
build-scan-terms-of-use-agree: "yes"
|
||||||
|
```
|
||||||
|
|
||||||
|
A Build Scan makes it easy to determine the source of any dependency vulnerabilities in your project.
|
||||||
|
|
||||||
|
### Configuration parameters
|
||||||
|
|
||||||
|
In some cases, the default action configuration will not be sufficient, and additional action parameters will need to be specified.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Generate and save dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
with:
|
||||||
|
# Use a particular Gradle version instead of the configured wrapper.
|
||||||
|
gradle-version: 8.6
|
||||||
|
|
||||||
|
# The gradle project is not in the root of the repository.
|
||||||
|
build-root-directory: my-gradle-project
|
||||||
|
|
||||||
|
# Choose a task that will trigger dependency resolution
|
||||||
|
dependency-resolution-task: myDependencyResolutionTask
|
||||||
|
|
||||||
|
# Additional arguments that should be passed to execute Gradle
|
||||||
|
additional-arguments: --no-configuration-cache
|
||||||
|
|
||||||
|
# Enable configuration-cache reuse for this build.
|
||||||
|
cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}
|
||||||
|
|
||||||
|
# Do not attempt to submit the dependency-graph. Save it as a workflow artifact.
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
|
||||||
|
# Specify the location where dependency graph files will be generated.
|
||||||
|
dependency-graph-report-dir: custom-report-dir
|
||||||
|
|
||||||
|
# By default, failure to generate a dependency graph will cause the workflow to fail
|
||||||
|
dependency-graph-continue-on-failure: true
|
||||||
|
|
||||||
|
```
|
||||||
|
|
||||||
|
See the [Action Metadata file](../dependency-submission/action.yml) for a more detailed description of each input parameter.
|
||||||
|
|
||||||
|
The `GitHub Dependency Graph Gradle Plugin` can be further
|
||||||
|
[configured via a number of environment variables](https://github.com/gradle/github-dependency-graph-gradle-plugin?#required-environment-variables).
|
||||||
|
These will be automatically set by the `dependency-submission` action, but you may override these values
|
||||||
|
by setting them explicitly in your workflow file.
|
||||||
|
|
||||||
|
# Resolving a dependency vulnerability
|
||||||
|
|
||||||
|
## Finding the source of a dependency vulnerability
|
||||||
|
|
||||||
|
Once you have submitted a dependency graph, you may receive Dependabot Alerts warning about vulnerabilities in
|
||||||
|
dependencies of your project. In the case of transitive dependencies, it may not be obvious how that dependency is
|
||||||
|
used or what you can do to address the vulnerability alert.
|
||||||
|
|
||||||
|
The first step to investigating a Dependabot Alert is to determine the source of the dependency. One of the best ways to
|
||||||
|
do so is with a free Develocity Build Scan®, which makes it easy to explore the dependencies resolved in your build.
|
||||||
|
|
||||||
|
<img width="1069" alt="image" src="https://github.com/gradle/actions/assets/179734/3a637dfd-396c-4e94-8332-dcc6eb5a35ac">
|
||||||
|
|
||||||
|
In this example, we are searching for dependencies matching the name 'com.squareup.okio:okio' in the _Build Dependencies_ of
|
||||||
|
the project. You can easily see that this dependency originates from 'com.github.ben-manes:gradle-versions-plugin'.
|
||||||
|
Knowing the source of the dependency can help determine how to deal with the Dependabot Alert.
|
||||||
|
|
||||||
|
Note that you may need to look at both the _Dependencies_ and the _Build Dependencies_ of your project to find the
|
||||||
|
offending dependency.
|
||||||
|
|
||||||
|
### When you cannot publish a Build Scan®
|
||||||
|
|
||||||
|
If publishing a free Build Scan to https://scans.gradle.com isn't an option, and you don't have access to a private [Develocity
|
||||||
|
server](https://gradle.com/) for your project, you can obtain information about the each resolved dependency by running the `dependency-submission` workflow with debug logging enabled.
|
||||||
|
|
||||||
|
The simplest way to do so is to re-run the dependency-submission job with debug logging enabled:
|
||||||
|
|
||||||
|
<img width="665" alt="image" src="https://github.com/gradle/actions/assets/179734/d95b889a-09fb-4731-91f2-baebbf647e31">
|
||||||
|
|
||||||
|
When you do so, the Gradle build that generates the dependency-graph will include a log message for each dependency version included in the graph.
|
||||||
|
Given the details in one log message, you can run (locally) the built-in [dependencyInsight](https://docs.gradle.org/current/userguide/viewing_debugging_dependencies.html#dependency_insights) task
|
||||||
|
to determine exactly how the dependency was resolved.
|
||||||
|
|
||||||
|
For example, given the following message in the logs:
|
||||||
|
```
|
||||||
|
Detected dependency 'com.google.guava:guava:32.1.3-jre': project = ':my-subproject', configuration = 'compileClasspath'
|
||||||
|
```
|
||||||
|
|
||||||
|
You would run the following command locally:
|
||||||
|
```
|
||||||
|
./gradlew :my-subproject:dependencyInsight --configuration compileClasspath --dependency com.google.guava:guava:32.1.3-jre
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Dealing with 'classpath' configuration
|
||||||
|
|
||||||
|
If the configuration value in the log message is "classpath" then instead of running `dependency-insight` you'll need to run the Gradle
|
||||||
|
`buildEnvironment` task.
|
||||||
|
|
||||||
|
For example, given the following message in the logs:
|
||||||
|
```
|
||||||
|
Detected dependency 'xerces:xercesImpl:2.12.2': project = ':my-subproject', configuration = 'classpath'
|
||||||
|
```
|
||||||
|
|
||||||
|
You would run the following command locally to expose the `xercesImpl` dependency:
|
||||||
|
```
|
||||||
|
./gradlew :my-subproject:buildEnvironment | grep -C 5 xercesImpl
|
||||||
|
```
|
||||||
|
|
||||||
|
## Updating the dependency version
|
||||||
|
|
||||||
|
Once you've discovered the source of the dependency, the most obvious fix is to update the dependency to a patched version that does not
|
||||||
|
suffer the vulnerability. For direct dependencies, this is often straightforward. But for transitive dependencies it can be tricky.
|
||||||
|
|
||||||
|
### Dependency source is specified directly in the build
|
||||||
|
|
||||||
|
If the dependency is used to compile your code or run your tests, it's normal for the underlying "source" of the dependency to have a
|
||||||
|
version configured directly in the build. For example, if you have a vulnerable version of `com.squareup.okio:okio` in your `compileClasspath`, then
|
||||||
|
it's likely you have a dependency like `com.squareup.moshi:moshi` configured as an `api` or `implementation` dependency.
|
||||||
|
|
||||||
|
In this case there are 2 possibilities:
|
||||||
|
1. There is a newer, compatible version of `com.squareup.moshi:moshi` available, and you can just bump the version number.
|
||||||
|
2. There isn't a newer, compatible version of `com.squareup.moshi:moshi`
|
||||||
|
|
||||||
|
In the second case, you can add a Dependency Constraint, to force the use of the newest version of `com.squareup.okio`:
|
||||||
|
|
||||||
|
```kotlin
|
||||||
|
dependencies {
|
||||||
|
implementation("com.squareup.moshi:moshi:1.12.0")
|
||||||
|
constraints {
|
||||||
|
// Force a newer version of okio in transitive resolution
|
||||||
|
implementation("com.squareup.okio:okio:3.6.0")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Dependency source is a plugin classpath
|
||||||
|
|
||||||
|
If the vulnerable dependency is introduced by a Gradle plugin, again the best option is to look for a newer version of the plugin.
|
||||||
|
But if none is available, you can still use a dependency constraint to force a newer transitive version to be used.
|
||||||
|
|
||||||
|
The dependency constraint must be added to the `classpath` configuration of the buildscript that loads the plugin.
|
||||||
|
|
||||||
|
```kotlin
|
||||||
|
buildscript {
|
||||||
|
repositories {
|
||||||
|
gradlePluginPortal()
|
||||||
|
}
|
||||||
|
dependencies {
|
||||||
|
constraints {
|
||||||
|
// Force a newer version of okio in transitive resolution
|
||||||
|
classpath("com.squareup.okio:okio:3.6.0")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
plugins {
|
||||||
|
id("com.github.ben-manes.versions") version("0.51.0")
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## Limiting the dependencies that appear in the dependency graph
|
||||||
|
|
||||||
|
By default, the `dependency-submission` action attempts to detect all dependencies declared and used by your Gradle build.
|
||||||
|
At times it may helpful to limit the dependencies reported to GitHub, to avoid security alerts for dependencies that
|
||||||
|
don't form a critical part of your product. For example, a vulnerability in the tool you use to generate documentation
|
||||||
|
may not be as important as a vulnerability in one of your runtime dependencies.
|
||||||
|
|
||||||
|
The `dependency-submission` action provides a convenient mechanism to filter the projects and configurations that
|
||||||
|
contribute to the dependency graph.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Ideally, all dependencies involved in building and testing a project will be extracted and reported in a dependency graph.
|
||||||
|
> These dependencies would be assigned to different scopes (eg development, runtime, testing) and the GitHub UI would make it easy to opt-in to security alerts for different dependency scopes.
|
||||||
|
> However, this functionality does not yet exist.
|
||||||
|
|
||||||
|
### Selecting Gradle projects that will contribute to the dependency graph
|
||||||
|
|
||||||
|
If you do not want the dependency graph to include dependencies from every project in your build,
|
||||||
|
you can easily exclude or include certain projects from the dependency extraction process.
|
||||||
|
|
||||||
|
To restrict which Gradle subprojects contribute to the report, specify which projects to exclude or include via a regular expression.
|
||||||
|
You can use the `dependency-graph-exclude-projects` and `dependency-graph-include-projects` input parameters for this purpose.
|
||||||
|
|
||||||
|
Note that excluding a project in this way only removes dependencies that are _resolved_ as part of that project, and may
|
||||||
|
not necessarily remove all dependencies _declared_ in that project. If another project depends on the excluded project
|
||||||
|
then it may transitively resolve dependencies declared in the excluded project: these dependencies will still be included
|
||||||
|
in the generated dependency graph.
|
||||||
|
|
||||||
|
### Selecting Gradle configurations that will contribute to the dependency graph
|
||||||
|
|
||||||
|
Similarly to Gradle projects, it is possible to exclude or include a set of dependency configurations from dependency graph generation,
|
||||||
|
so that only dependencies resolved by the included configurations are reported.
|
||||||
|
|
||||||
|
To restrict which Gradle configurations contribute to the report, specify which configurations to exclude or include via a regular expression.
|
||||||
|
You can use the `dependency-graph-exclude-configurations` and `dependency-graph-include-configurations` input parameters for this purpose.
|
||||||
|
|
||||||
|
Note that configuration exclusion applies to the configuration in which the dependency is _resolved_ which is not necessarily
|
||||||
|
the configuration where the dependency is _declared_. For example if you decare a dependency as `implementation` in
|
||||||
|
a Java project, that dependency will be resolved in `compileClasspath`, `runtimeClasspath` and possibly other configurations.
|
||||||
|
|
||||||
|
### Example of project and configuration filtering
|
||||||
|
|
||||||
|
For example, if you want to exclude dependencies resolved by the `buildSrc` project, and exclude dependencies from the `testCompileClasspath` and `testRuntimeClasspath` configurations, you would use the following configuration:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
with:
|
||||||
|
# Exclude all dependencies that originate solely in the 'buildSrc' project
|
||||||
|
dependency-graph-exclude-projets: ':buildSrc'
|
||||||
|
# Exclude dependencies that are only resolved in test classpaths
|
||||||
|
dependency-graph-exclude-configurations: '.*[Tt]est(Compile|Runtime)Classpath'
|
||||||
|
```
|
||||||
|
|
||||||
|
# Advance usage scenarios
|
||||||
|
|
||||||
|
## Using a custom plugin repository
|
||||||
|
|
||||||
|
By default, the action downloads the `github-dependency-graph-gradle-plugin` from the Gradle Plugin Portal (https://plugins.gradle.org). If your GitHub Actions environment does not have access to this URL, you can specify a custom plugin repository to use with an environment variable.
|
||||||
|
|
||||||
|
See [the setup-gradle docs](setup-gradle.md#using-a-custom-plugin-repository) for details.
|
||||||
|
|
||||||
|
## Integrating the `dependency-review-action`
|
||||||
|
|
||||||
|
The GitHub [dependency-review-action](https://github.com/actions/dependency-review-action) helps you
|
||||||
|
understand dependency changes (and the security impact of these changes) for a pull request,
|
||||||
|
by comparing the dependency graph for the pull-request with that of the HEAD commit.
|
||||||
|
|
||||||
|
Example of a pull request workflow that executes a build for a pull request and runs the `dependency-review-action`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: Dependency review for pull requests
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-submission:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Generate and submit dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
|
||||||
|
- name: Perform dependency review
|
||||||
|
uses: actions/dependency-review-action@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
## Usage with pull requests from public forked repositories
|
||||||
|
|
||||||
|
This `contents: write` permission is [not available for any workflow that is triggered by a pull request submitted from a public forked repository](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token).
|
||||||
|
This limitation is designed to prevent a malicious pull request from effecting repository changes.
|
||||||
|
|
||||||
|
Because of this restriction, we require 2 separate workflows in order to generate and submit a dependency graph:
|
||||||
|
1. The first workflow runs directly against the pull request sources and will `generate-and-upload` the dependency graph.
|
||||||
|
2. The second workflow is triggered on `workflow_run` of the first workflow, and will `download-and-submit` the previously saved dependency graph.
|
||||||
|
|
||||||
|
***Main workflow file***
|
||||||
|
```yaml
|
||||||
|
name: Generate and save dependency graph
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read # 'write' permission is not available
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-submission:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Generate and save dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-upload
|
||||||
|
```
|
||||||
|
|
||||||
|
***Dependent workflow file***
|
||||||
|
```yaml
|
||||||
|
name: Download and submit dependency graph
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_run:
|
||||||
|
workflows: ['Generate and save dependency graph']
|
||||||
|
types: [completed]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
actions: read
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
submit-dependency-graph:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Download and submit dependency graph
|
||||||
|
uses: gradle/actions/dependency-submission@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: download-and-submit # Download saved dependency-graph and submit
|
||||||
|
```
|
||||||
|
|
||||||
|
### Integrating `dependency-review-action` for pull requests from public forked repositories
|
||||||
|
|
||||||
|
To integrate the `dependency-review-action` into the pull request workflows above, a third workflow file is required.
|
||||||
|
This workflow will be triggered directly on `pull_request`, but will wait until the dependency graph results are
|
||||||
|
submitted before the dependency review can complete. The period to wait is controlled by the `retry-on-snapshot-warnings` input parameters.
|
||||||
|
|
||||||
|
Here's an example of a separate "Dependency Review" workflow that will wait for 10 minutes for the above PR check workflow to complete.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: dependency-review
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-review:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: 'Dependency Review'
|
||||||
|
uses: actions/dependency-review-action@v3
|
||||||
|
with:
|
||||||
|
retry-on-snapshot-warnings: true
|
||||||
|
retry-on-snapshot-warnings-timeout: 600
|
||||||
|
```
|
||||||
|
|
||||||
|
The `retry-on-snapshot-warnings-timeout` (in seconds) needs to be long enough to allow the entire `Generate and save dependency graph` and `Download and submit dependency graph` workflows (above) to complete.
|
||||||
|
|
||||||
|
# Gradle version compatibility
|
||||||
|
|
||||||
|
Dependency-graph generation is compatible with most versions of Gradle >= `5.2`, and is tested regularly against
|
||||||
|
Gradle versions `5.2.1`, `5.6.4`, `6.0.1`, `6.9.4`, `7.1.1` and `7.6.3`, as well as all patched versions of Gradle 8.x.
|
||||||
|
|
||||||
|
A known exception to this is that Gradle `7.0`, `7.0.1` and `7.0.2` are not supported.
|
||||||
|
|
||||||
|
See [here](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#gradle-compatibility) for complete compatibility information.
|
||||||
|
|
||||||
|
# Additional references
|
||||||
|
|
||||||
|
- Dependency Submission Demo repository: https://github.com/gradle/github-dependency-submission-demo
|
||||||
|
- GitHub Dependency Graph Gradle Plugin: https://github.com/gradle/github-dependency-graph-gradle-plugin
|
||||||
|
- Webinar - Gradle at Scale with GitHub and GitHub Actions at Allegro: https://www.youtube.com/watch?v=gV94I28FPos
|
||||||
|
|
||||||
162
docs/deprecation-upgrade-guide.md
Normal file
162
docs/deprecation-upgrade-guide.md
Normal file
@@ -0,0 +1,162 @@
|
|||||||
|
# Deprecation upgrade guide
|
||||||
|
|
||||||
|
As these actions evolve, certain inputs, behaviour and usages are deprecated for removal.
|
||||||
|
Deprecated functionality will be fully supported during the current major release, and will be
|
||||||
|
removed in the next major release.
|
||||||
|
Users will receive a deprecation warning when they rely on deprecated functionality,
|
||||||
|
prompting them to update their workflows.
|
||||||
|
|
||||||
|
## The action `gradle/gradle-build-action` has been replaced by `gradle/actions/setup-gradle`
|
||||||
|
|
||||||
|
The `gradle-build-action` action has evolved, so that the core functionality is now to configure the
|
||||||
|
Gradle environment for GitHub Actions. For clarity and consistency with other action (eg `setup-java`, `setup-node`), the `gradle-build-action` has been replaced by the `setup-gradle` action.
|
||||||
|
|
||||||
|
As of `v3.x`, the `setup-gradle` and `gradle-build-action` actions are functionally identical,
|
||||||
|
and are released with the same versions.
|
||||||
|
|
||||||
|
To convert your workflows, simply replace:
|
||||||
|
```
|
||||||
|
uses: gradle/gradle-build-action@v3
|
||||||
|
```
|
||||||
|
with
|
||||||
|
```
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
## The action `gradle/wrapper-validation-action` has been replaced by `gradle/actions/wrapper-validation`
|
||||||
|
|
||||||
|
To facilitate ongoing development, the `wrapper-validation-action` action implementation has been merged into
|
||||||
|
the https://github.com/gradle/actions repository, and the `gradle/wrapper-validation-action` has been replaced by the `gradle/actions/wrapper-validation` action.
|
||||||
|
|
||||||
|
As of `v3.x`, the `gradle/wrapper-validation-action` and `gradle/actions/wrappper-validation` actions are
|
||||||
|
functionally identical, and are released with the same versions.
|
||||||
|
|
||||||
|
In a future major version (likely `v4.x`) we will stop releasing new versions of `gradle/wrapper-validation-action`:
|
||||||
|
development and releases will continue in the `gradle/actions/wrapper-validation` action.
|
||||||
|
|
||||||
|
To convert your workflows, simply replace:
|
||||||
|
```
|
||||||
|
uses: gradle/wrapper-validation-action@v3
|
||||||
|
```
|
||||||
|
with
|
||||||
|
```
|
||||||
|
uses: gradle/actions/wrapper-validation@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
## Using the action to execute Gradle via the `arguments` parameter is deprecated
|
||||||
|
|
||||||
|
The core functionality of the `setup-gradle` (and `gradle-build-action`) actions is to configure your
|
||||||
|
Gradle environment for GitHub Actions. Once the action has run, any subsequent Gradle executions will
|
||||||
|
benefit from caching, reporting and other features of the action.
|
||||||
|
|
||||||
|
Using the `arguments` parameter to execute Gradle directly is not necessary to benefit from this action.
|
||||||
|
This input is deprecated, and will be removed in the `v4` major release of the action.
|
||||||
|
|
||||||
|
To convert your workflows, replace any steps using the `arguments` parameter with 2 steps: one to `setup-gradle` and another that runs your Gradle build.
|
||||||
|
|
||||||
|
For example, given a workflow like this:
|
||||||
|
|
||||||
|
```
|
||||||
|
steps:
|
||||||
|
- name: Assemble the project
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
arguments: 'assemble'
|
||||||
|
|
||||||
|
- name: Run the tests
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
arguments: 'test'
|
||||||
|
|
||||||
|
- name: Run build in a subdirectory
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
build-root-directory: another-build
|
||||||
|
arguments: 'build'
|
||||||
|
```
|
||||||
|
|
||||||
|
Then replace this with a single call to `setup-gradle` together with separate `run` steps to execute your build.
|
||||||
|
The exact syntax depends on whether or not your project is configured with the [Gradle wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html).
|
||||||
|
|
||||||
|
##### Project uses Gradle wrapper
|
||||||
|
|
||||||
|
```
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
|
||||||
|
- name: Assemble the project
|
||||||
|
run: ./gradlew assemble
|
||||||
|
|
||||||
|
- name: Run the tests
|
||||||
|
run: ./gradlew test
|
||||||
|
|
||||||
|
- name: Run build in a subdirectory
|
||||||
|
working-directory: another-build
|
||||||
|
run: ./gradlew build
|
||||||
|
```
|
||||||
|
|
||||||
|
##### Project doesn't use Gradle wrapper
|
||||||
|
|
||||||
|
```
|
||||||
|
- name: Setup Gradle for a non-wrapper project
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
gradle-version: 8.9
|
||||||
|
|
||||||
|
- name: Assemble the project
|
||||||
|
run: gradle assemble
|
||||||
|
|
||||||
|
- name: Run the tests
|
||||||
|
run: gradle test
|
||||||
|
|
||||||
|
- name: Run build in a subdirectory
|
||||||
|
working-directory: another-build
|
||||||
|
run: gradle build
|
||||||
|
```
|
||||||
|
|
||||||
|
Using the action in this way gives you more control over how Gradle is executed, while still giving you
|
||||||
|
all of the benefits of the `setup-gradle` action.
|
||||||
|
|
||||||
|
The `arguments` parameter is scheduled to be removed in `setup-gradle@v4`.
|
||||||
|
|
||||||
|
Note: if you are using the `gradle-build-action`, [see here](#the-action-gradlegradle-build-action-has-been-replaced-by-gradleactionssetup-gradle) for more details on how to migrate.
|
||||||
|
|
||||||
|
## The `build-scan-terms-of-service` input parameters have been renamed
|
||||||
|
|
||||||
|
With recent releases of the `com.gradle.develocity` plugin, key input parameters have been renamed.
|
||||||
|
- `build-scan-terms-of-service-url` is now `build-scan-terms-of-use-url`
|
||||||
|
- `build-scan-terms-of-service-agree` is now `build-scan-terms-of-use-agree`
|
||||||
|
|
||||||
|
The standard URL for the terms of use has also changed to https://gradle.com/help/legal-terms-of-use
|
||||||
|
|
||||||
|
To convert your workflows, change:
|
||||||
|
```
|
||||||
|
build-scan-publish: true
|
||||||
|
build-scan-terms-of-service-url: "https://gradle.com/terms-of-service"
|
||||||
|
build-scan-terms-of-service-agree: "yes"
|
||||||
|
```
|
||||||
|
|
||||||
|
to this:
|
||||||
|
```
|
||||||
|
build-scan-publish: true
|
||||||
|
build-scan-terms-of-use-url: "https://gradle.com/help/legal-terms-of-use"
|
||||||
|
build-scan-terms-of-use-agree: "yes"
|
||||||
|
```
|
||||||
|
These deprecated build-scan parameters are scheduled to be removed in `setup-gradle@v4` and `dependency-submission@v4`.
|
||||||
|
|
||||||
|
## The GRADLE_ENTERPRISE_ACCESS_KEY env var is deprecated
|
||||||
|
Gradle Enterprise has been renamed to Develocity starting from Gradle plugin 3.17 and Develocity server 2024.1.
|
||||||
|
In v4 release of the action, it will require setting the access key with the `develocity-access-key` input and Develocity 2024.1 at least to generate short-lived tokens.
|
||||||
|
If those requirements are not met, the `GRADLE_ENTERPRISE_ACCESS_KEY` env var will be cleared out and build scan publication or other authenticated Develocity operations won't be possible.
|
||||||
|
|
||||||
|
## The `gradle-home-cache-cleanup` input parameter has been replaced by `cache-cleanup`
|
||||||
|
|
||||||
|
In versions of the action prior to `v4`, the boolean `gradle-home-cache-cleanup` parameter allows users to opt-in
|
||||||
|
to cache cleanup, removing unused files in Gradle User Home prior to saving to the cache.
|
||||||
|
|
||||||
|
With `v4`, cache-cleanup is enabled by default, and controlled by the `cache-cleanup` input parameter.
|
||||||
|
|
||||||
|
To remove this deprecation:
|
||||||
|
- If you are using `gradle-home-cache-cleanup: true` in your workflow, you can remove this option as this is now enabled by default.
|
||||||
|
- If you want cache-cleanup to run even when a Gradle build fails, then add the `cache-cleanup: always` input.
|
||||||
|
- If cache-cleanup is causing problems with your workflow, you can disable it with `cache-cleanup: never`.
|
||||||
862
docs/setup-gradle.md
Normal file
862
docs/setup-gradle.md
Normal file
@@ -0,0 +1,862 @@
|
|||||||
|
# Configure Gradle for GitHub Actions workflows
|
||||||
|
|
||||||
|
This GitHub Action can be used to configure Gradle for optimal execution on any platform supported by GitHub Actions.
|
||||||
|
|
||||||
|
## Why use the `setup-gradle` action?
|
||||||
|
|
||||||
|
It is possible to directly invoke Gradle in your workflow, and the `actions/setup-java@v4` action provides a simple way to cache Gradle dependencies.
|
||||||
|
|
||||||
|
However, the `setup-gradle` action offers a several advantages over this approach:
|
||||||
|
|
||||||
|
- Easily [configure your workflow to use a specific version of Gradle](#build-with-a-specific-gradle-version) using the `gradle-version` parameter. Gradle distributions are automatically downloaded and cached.
|
||||||
|
- More sophisticated and more efficient caching of Gradle User Home between invocations, compared to `setup-java` and most custom configurations using `actions/cache`. [More details below](#caching-build-state-between-jobs).
|
||||||
|
- Detailed reporting of cache usage and cache configuration options allow you to [optimize the use of the GitHub actions cache](#optimizing-cache-effectiveness).
|
||||||
|
- [Generate and Submit a GitHub Dependency Graph](#github-dependency-graph-support) for your project, enabling Dependabot security alerts.
|
||||||
|
- [Automatic capture of Build Scan® links](#build-reporting) from the build, making them easier to locate in workflow runs.
|
||||||
|
|
||||||
|
The `setup-gradle` action is designed to provide these benefits with minimal configuration.
|
||||||
|
These features work both when Gradle is executed via `setup-gradle` and for any Gradle execution in subsequent steps.
|
||||||
|
|
||||||
|
## General usage
|
||||||
|
|
||||||
|
The `setup-gradle` action works by configuring environment variables and by adding a set of Gradle init-scripts to the Gradle User Home. These will apply to all Gradle executions on the runner, no matter how Gradle is invoked.
|
||||||
|
This means that if you have an existing workflow that executes Gradle with a `run` step, you can add an initial "Setup Gradle" Step to benefit from caching, build-scan capture, and other features of this action.
|
||||||
|
|
||||||
|
The recommended way to execute any Gradle build is with the help of the [Gradle Wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html), and the following examples assume that the Gradle Wrapper has been configured for the project. See [this example](#build-with-a-specific-gradle-version) if your project doesn't use the Gradle Wrapper.
|
||||||
|
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: Run Gradle on every push
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
gradle:
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
os: [ubuntu-latest, macos-latest, windows-latest]
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
|
||||||
|
- name: Execute Gradle build
|
||||||
|
run: ./gradlew build
|
||||||
|
```
|
||||||
|
|
||||||
|
## Build with a specific Gradle version
|
||||||
|
|
||||||
|
The `setup-gradle` action can download and install a specified Gradle version, adding this installed version to the PATH.
|
||||||
|
Downloaded Gradle versions are stored in the GitHub Actions cache, to avoid having to download them again later.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle 8.5
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
gradle-version: 8.5
|
||||||
|
- name: Build with Gradle 8.5
|
||||||
|
run: gradle build
|
||||||
|
```
|
||||||
|
|
||||||
|
The `gradle-version` parameter can be set to any valid Gradle version.
|
||||||
|
|
||||||
|
Moreover, you can use the following aliases:
|
||||||
|
|
||||||
|
| Alias | Selects |
|
||||||
|
| --- |---|
|
||||||
|
| `wrapper` | The Gradle wrapper's version (default, useful for matrix builds) |
|
||||||
|
| `current` | The current [stable release](https://gradle.org/install/) |
|
||||||
|
| `release-candidate` | The current [release candidate](https://gradle.org/release-candidate/) if any, otherwise fallback to `current` |
|
||||||
|
| `nightly` | The latest [nightly](https://gradle.org/nightly/), fails if none. |
|
||||||
|
| `release-nightly` | The latest [release nightly](https://gradle.org/release-nightly/), fails if none. |
|
||||||
|
|
||||||
|
This can be handy to automatically verify your build works with the latest release candidate of Gradle:
|
||||||
|
|
||||||
|
The actual Gradle version used is available as an action output: `gradle-version`.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: Test latest Gradle RC
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: 0 0 * * * # daily
|
||||||
|
jobs:
|
||||||
|
gradle-rc:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- uses: gradle/actions/setup-gradle@v3
|
||||||
|
id: setup-gradle
|
||||||
|
with:
|
||||||
|
gradle-version: release-candidate
|
||||||
|
- run: gradle build --dry-run # just test build configuration
|
||||||
|
- run: echo "The release-candidate version was ${{ steps.setup-gradle.outputs.gradle-version }}"
|
||||||
|
```
|
||||||
|
|
||||||
|
## Caching build state between Jobs
|
||||||
|
|
||||||
|
The `setup-gradle` action will use the GitHub Actions cache to save and restore reusable state that may speed up subsequent build invocations. This includes most content that is downloaded from the internet as part of a build, as well as expensive to create content like compiled build scripts, transformed Jar files, etc.
|
||||||
|
|
||||||
|
The cached state includes:
|
||||||
|
- Any distributions downloaded to satisfy a `gradle-version` parameter.
|
||||||
|
- A subset of the Gradle User Home directory, including downloaded dependencies, wrapper distributions, and the local build cache.
|
||||||
|
|
||||||
|
To reduce the space required for caching, this action attempts to reduce duplication in cache entries on a best effort basis.
|
||||||
|
|
||||||
|
The state will be restored from the cache during the first `setup-gradle` step for any workflow job, and cache entries will be written back to the cache at the end of the job after all Gradle executions have been completed.
|
||||||
|
|
||||||
|
### Disabling caching
|
||||||
|
|
||||||
|
Caching is enabled by default. You can disable caching for the action as follows:
|
||||||
|
```yaml
|
||||||
|
cache-disabled: true
|
||||||
|
```
|
||||||
|
|
||||||
|
### Using the cache read-only
|
||||||
|
|
||||||
|
By default, The `setup-gradle` action will only write to the cache from Jobs on the default (`main`/`master`) branch.
|
||||||
|
Jobs on other branches will read entries from the cache but will not write updated entries.
|
||||||
|
See [Optimizing cache effectiveness](#select-which-branches-should-write-to-the-cache) for a more detailed explanation.
|
||||||
|
|
||||||
|
In some circumstances, it makes sense to change this default and configure a workflow Job to read existing cache entries but not to write changes back.
|
||||||
|
|
||||||
|
You can configure read-only caching for `setup-gradle` as follows:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
cache-read-only: true
|
||||||
|
```
|
||||||
|
|
||||||
|
You can also configure read-only caching only for certain branches:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# Only write to the cache for builds on the 'main' and 'release' branches. (Default is 'main' only.)
|
||||||
|
# Builds on other branches will only read existing entries from the cache.
|
||||||
|
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/release' }}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Using the cache write-only
|
||||||
|
|
||||||
|
In certain circumstances it may be desirable to start with a clean Gradle User Home state, but to save the state at the end of a workflow Job:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
cache-write-only: true
|
||||||
|
```
|
||||||
|
|
||||||
|
### Configuring cache cleanup
|
||||||
|
|
||||||
|
The Gradle User Home directory tends to grow over time. When you switch to a new Gradle wrapper version
|
||||||
|
or upgrade a dependency version the old files are not automatically and immediately removed.
|
||||||
|
While this can make sense in a local environment, in a GitHub Actions environment
|
||||||
|
it can lead to ever-larger Gradle User Home cache entries being saved and restored.
|
||||||
|
|
||||||
|
To avoid this situation, the `setup-gradle` and `dependency-submission` actions will perform "cache-cleanup",
|
||||||
|
purging any unused files from the Gradle User Home before saving it to the GitHub Actions cache.
|
||||||
|
Cache cleanup will attempt to remove any files that are initially restored to the Gradle User Home directory
|
||||||
|
but that are not used used by Gradle during the GitHub Actions Workflow.
|
||||||
|
|
||||||
|
If a Gradle build fails when running the Job, then it is possible that some required files and dependencies
|
||||||
|
will not be touched during the Job. To prevent these files from being purged, the default behavior is for
|
||||||
|
cache cleanup to run only when all Gradle builds in the Job are successful.
|
||||||
|
|
||||||
|
Gradle Home cache cleanup is enabled by default, and can be controlled by the `cache-cleanup` parameter as follows:
|
||||||
|
- `cache-cleanup: always`: Always run cache cleanup, even when a Gradle build fails in the Job.
|
||||||
|
- `cache-cleanup: on-success` (default): Run cache cleanup when the Job contains no failing Gradle builds.
|
||||||
|
- `cache-cleanup: never`: Disable cache cleanup for the Job.
|
||||||
|
|
||||||
|
Cache cleanup will never run when the cache is configured as read-only or disabled.
|
||||||
|
|
||||||
|
### Overwriting an existing Gradle User Home
|
||||||
|
|
||||||
|
When the action detects that the Gradle User Home caches directory already exists (`$GRADLE_USER_HOME/caches`), then by default it will not overwrite the existing content of this directory.
|
||||||
|
This can occur when a prior action initializes this directory, or when using a self-hosted runner that retains this directory between uses.
|
||||||
|
|
||||||
|
In this case, the Job Summary will display a message like:
|
||||||
|
> Caching for Gradle actions was disabled due to pre-existing Gradle User Home
|
||||||
|
|
||||||
|
If you want to override the default and have the caches of the `setup-gradle` action overwrite existing content in the Gradle User Home, you can set the `cache-overwrite-existing` parameter to `true`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
cache-overwrite-existing: true
|
||||||
|
```
|
||||||
|
|
||||||
|
### Saving configuration-cache data
|
||||||
|
|
||||||
|
When Gradle is executed with the [configuration-cache](https://docs.gradle.org/current/userguide/configuration_cache.html) enabled, the configuration-cache data is stored
|
||||||
|
in the project directory, at `<project-dir>/.gradle/configuration-cache`. Due to the way the configuration-cache works, [this file may contain stored credentials and other
|
||||||
|
secrets](https://docs.gradle.org/release-nightly/userguide/configuration_cache.html#config_cache:secrets), and this data needs to be encrypted to be safely stored in the GitHub Actions cache.
|
||||||
|
|
||||||
|
To benefit from configuration caching in your GitHub Actions workflow, you must:
|
||||||
|
- Execute your build with Gradle 8.6 or newer. This can be achieved directly or via the Gradle Wrapper.
|
||||||
|
- Enable the configuration cache for your build.
|
||||||
|
- Generate a [valid Gradle encryption key](https://docs.gradle.org/8.6/userguide/configuration_cache.html#config_cache:secrets:configuring_encryption_key) and save it as a [GitHub Actions secret](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions).
|
||||||
|
- Provide the secret key via the `cache-encryption-key` action parameter.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
jobs:
|
||||||
|
gradle-with-configuration-cache:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
gradle-version: 8.6
|
||||||
|
cache-encryption-key: ${{ secrets.GradleEncryptionKey }}
|
||||||
|
- run: gradle build --configuration-cache
|
||||||
|
```
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> The configuration cache cannot be saved or restored in workflows triggered by a pull requests from a repository fork.
|
||||||
|
> This is because [GitHub secrets are not passed to workflows triggered by PRs from forks](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#using-secrets-in-a-workflow).
|
||||||
|
> This prevents a malicious PR from reading the configuration-cache data, which may encode secrets read by Gradle.
|
||||||
|
|
||||||
|
### Incompatibility with other caching mechanisms
|
||||||
|
|
||||||
|
When using `setup-gradle` we recommend that you avoid using other mechanisms to save and restore the Gradle User Home.
|
||||||
|
|
||||||
|
Specifically:
|
||||||
|
- Avoid using `actions/cache` configured to cache the Gradle User Home, [as described in this example](https://github.com/actions/cache/blob/main/examples.md#java---gradle).
|
||||||
|
- Avoid using `actions/setup-java` with the `cache: gradle` option, [as described here](https://github.com/actions/setup-java#caching-gradle-dependencies).
|
||||||
|
|
||||||
|
Using either of these mechanisms may interfere with the caching provided by this action. If you choose to use a different mechanism to save and restore the Gradle User Home, you should disable the caching provided by this action, as described above.
|
||||||
|
|
||||||
|
## How Gradle User Home caching works
|
||||||
|
|
||||||
|
### Properties of the GitHub Actions cache
|
||||||
|
|
||||||
|
The GitHub Actions cache has some properties that present problems for efficient caching of the Gradle User Home.
|
||||||
|
- Immutable entries: once a cache entry is written for a key, it cannot be overwritten or changed.
|
||||||
|
- Branch scope: cache entries written for a Git branch are not visible from actions running against different branches or tags. Entries written for the default branch are visible to all. https://docs.github.com/en/actions/using-workflows/caching-dependencies-to-speed-up-workflows#restrictions-for-accessing-a-cache
|
||||||
|
- Restore keys: if no exact match is found, a set of partial keys can be provided that will match by cache key prefix. https://docs.github.com/en/actions/using-workflows/caching-dependencies-to-speed-up-workflows#matching-a-cache-key
|
||||||
|
|
||||||
|
Each of these properties has influenced the design and implementation of the caching in `setup-gradle`, as described below.
|
||||||
|
|
||||||
|
### Which content is cached
|
||||||
|
|
||||||
|
Using experiments and observations, we have attempted to identify which Gradle User Home content is worth saving and restoring between build invocations. We considered both the respective size of the content and the impact this content has on build times. As well as the obvious candidates like downloaded dependencies, we saw that compiled build scripts, transformed Jar files, and other content can also have a significant impact.
|
||||||
|
|
||||||
|
In the end, we opted to save and restore as much content as is practical, including:
|
||||||
|
- `caches/<version>/generated-gradle-jars`: These files are generated on the first use of a particular Gradle version, and are expensive to recreate
|
||||||
|
- `caches/<version>/kotlin-dsl` and `caches/<version>/scripts`: These are the compiled build scripts. The Kotlin ones in particular can benefit from caching.
|
||||||
|
- `caches/modules-2`: The downloaded dependencies
|
||||||
|
- `caches/transforms-3`: The results of artifact transforms
|
||||||
|
- `caches/jars-9`: Jar files that have been processed/instrumented by Gradle
|
||||||
|
- `caches/build-cache-1`: The local build cache
|
||||||
|
|
||||||
|
In certain cases, a particular section of Gradle User Home will be too large to make caching effective. In these cases, particular subdirectories can be excluded from caching. See [Exclude content from Gradle User Home cache](#exclude-content-from-gradle-user-home-cache).
|
||||||
|
|
||||||
|
### Cache keys
|
||||||
|
|
||||||
|
The actual content of the Gradle User Home after a build is the result of many factors, including:
|
||||||
|
- Core Gradle build files (`settings.gradle[.kts]`, `build.gradle[.kts]`, `gradle.properties`)
|
||||||
|
- Associated Gradle configuration files (`gradle-wrapper.properties`, `dependencies.toml`, etc)
|
||||||
|
- The entire content of `buildSrc` or any included builds that provide plugins.
|
||||||
|
- The entire content of the repository, in the case of the local build cache.
|
||||||
|
- The actual build command that was invoked, including system properties and environment variables.
|
||||||
|
|
||||||
|
For this reason, it's very difficult to create a cache key that will deterministically map to a saved Gradle User Home state. So instead of trying to reliably hash all of these inputs to generate a cache key, the Gradle User Home cache key is based on the currently executing Job and the current commit hash for the repository.
|
||||||
|
|
||||||
|
The Gradle User Home cache key is composed of:
|
||||||
|
- The current operating system (`RUNNER_OS`)
|
||||||
|
- The Job id
|
||||||
|
- A hash of the Job matrix parameters and the workflow name
|
||||||
|
- The git SHA for the latest commit
|
||||||
|
|
||||||
|
Specifically, the cache key is: `${cache-protocol}-gradle|${runner-os}|${job-id}[${hash-of-job-matrix-and-workflow-name}]-${git-sha}`
|
||||||
|
|
||||||
|
As such, the cache key is likely to change on each subsequent run of GitHub actions.
|
||||||
|
This allows the most recent state to always be available in the GitHub actions cache.
|
||||||
|
|
||||||
|
### Finding a matching cache entry
|
||||||
|
|
||||||
|
In most cases, no exact match will exist for the cache key. Instead, the Gradle User Home will be restored for the closest matching cache entry, using a set of "restore keys". The entries will be matched with the following precedence:
|
||||||
|
- An exact match on OS, job id, workflow name, matrix, and Git SHA
|
||||||
|
- The most recent entry saved for the same OS, job id, workflow name, and matrix values
|
||||||
|
- The most recent entry saved for the same OS and job id
|
||||||
|
- The most recent entry saved for the same OS
|
||||||
|
|
||||||
|
Due to branch scoping of cache entries, the above match will be first performed for entries from the same branch, and then for the default ('main') branch.
|
||||||
|
|
||||||
|
After the Job is complete, the current Gradle User Home state will be collected and written as a new cache entry with the complete cache key. Old entries will be expunged from the GitHub Actions cache on a least recently used basis.
|
||||||
|
|
||||||
|
Note that while effective, this mechanism is not inherently efficient. It requires the entire Gradle User Home directory to be stored separately for each branch, for every OS+Job+Matrix combination. In addition, it writes a new cache entry on every GitHub Actions run.
|
||||||
|
|
||||||
|
This inefficiency is effectively mitigated by [Deduplication of Gradle User Home cache entries](#deduplication-of-gradle-user-home-cache-entries) and can be further optimized for a workflow using the techniques described in [Optimizing cache effectiveness](#optimizing-cache-effectiveness).
|
||||||
|
|
||||||
|
### Deduplication of Gradle User Home cache entries
|
||||||
|
|
||||||
|
To reduce duplication between cache entries, certain artifacts in Gradle User Home are extracted and cached independently based on their identity. This allows each Gradle User Home cache entry to be relatively small, sharing common elements between them without duplication.
|
||||||
|
|
||||||
|
Artifacts that are cached independently include:
|
||||||
|
- Downloaded dependencies
|
||||||
|
- Downloaded wrapper distributions
|
||||||
|
- Generated Gradle API jars
|
||||||
|
- Downloaded Java Toolchains
|
||||||
|
|
||||||
|
For example, this means that all jobs executing a particular version of the Gradle wrapper will share a single common entry for this wrapper distribution and one for each of the generated Gradle API jars.
|
||||||
|
|
||||||
|
### Stopping the Gradle daemon
|
||||||
|
|
||||||
|
By default, the action will stop all running Gradle daemons in the post-action step, before saving the Gradle User Home state.
|
||||||
|
This allows for any Gradle User Home cleanup to occur, and avoid file-locking issues on Windows.
|
||||||
|
|
||||||
|
If caching is disabled or the cache is in read-only mode, the daemon will not be stopped and will continue running after the job is completed.
|
||||||
|
|
||||||
|
## Optimizing cache effectiveness
|
||||||
|
|
||||||
|
Cache storage space for GitHub actions is limited, and writing new cache entries can trigger the deletion of existing entries.
|
||||||
|
Eviction of shared cache entries can reduce cache effectiveness, slowing down your `setup-gradle` steps.
|
||||||
|
|
||||||
|
There are a several actions you can take if your cache use is less effective due to entry eviction.
|
||||||
|
|
||||||
|
At the end of a Job, The `setup-gradle` action will write a summary of the Gradle builds executed, together with a detailed report of the cache entries that were read and written during the Job. This report can provide valuable insights that may help to determine the right way to optimize the cache usage for your workflow.
|
||||||
|
|
||||||
|
### Select which jobs should write to the cache
|
||||||
|
|
||||||
|
Consider a workflow that first runs a Job "compile-and-unit-test" to compile the code and run some basic unit tests, which is followed by a matrix of parallel "integration-test" jobs that each run a set of integration tests for the repository. Each "integration test" Job requires all of the dependencies required by "compile-and-unit-test", and possibly one or 2 additional dependencies.
|
||||||
|
|
||||||
|
By default, a new cache entry will be written on completion of each integration test job. If no additional dependencies were downloaded then this cache entry will share the "dependencies" entry with the "compile-and-unit-test" job, but if a single dependency was downloaded then an entirely new "dependencies" entry would be written. (The `setup-gradle` action does not _yet_ support a layered cache that could do this more efficiently). If each of these "integration-test" entries with their different "dependencies" entries is too large, then it could result in other important entries being evicted from the GitHub Actions cache.
|
||||||
|
|
||||||
|
Some techniques can be used to avoid/mitigate this issue:
|
||||||
|
- Configure the "integration-test" jobs with `cache-read-only: true`, meaning that the Job will use the entry written by the "compile-and-unit-test" job. This will avoid the overhead of cache entries for each of these jobs, at the expense of re-downloading any additional dependencies required by "integration-test".
|
||||||
|
- Add a step to the "compile-and-unit-test" job which downloads all dependencies required by the integration-test jobs but does not execute the tests. This will allow the "dependencies" entry for "compile-and-unit-test" to be shared among all cache entries for "integration-test". The resulting "integration-test" entries should be much smaller, reducing the potential for eviction.
|
||||||
|
- Combine the above 2 techniques, so that no cache entry is written by "integration-test" jobs, but all required dependencies are already present from the restored "compile-and-unit-test" entry.
|
||||||
|
|
||||||
|
### Select which branches should write to the cache
|
||||||
|
|
||||||
|
GitHub cache entries are not shared between builds on different branches or tags.
|
||||||
|
Workflow runs can _only_ restore caches created in either the same branch or the default branch (usually `main`).
|
||||||
|
This means that each branch will have its own Gradle User Home cache scope, and will not benefit from cache entries written for other (non-default) branches.
|
||||||
|
|
||||||
|
By default, The `setup-gradle` action will only _write_ to the cache for builds run on the default (`master`/`main`) branch.
|
||||||
|
Jobs running on other branches will only read from the cache. In most cases, this is the desired behavior.
|
||||||
|
This is because Jobs running on other branches will benefit from the cached Gradle User Home from `main`,
|
||||||
|
without writing private cache entries which could lead to evicting these shared entries.
|
||||||
|
|
||||||
|
If you have other long-lived development branches that would benefit from writing to the cache,
|
||||||
|
you can configure this by disabling the `cache-read-only` action parameter for these branches.
|
||||||
|
See [Using the cache read-only](#using-the-cache-read-only) for more details.
|
||||||
|
|
||||||
|
Note there are some cases where writing cache entries is typically unhelpful (these are disabled by default):
|
||||||
|
- For `pull_request` triggered runs, the cache scope is limited to the merge ref (`refs/pull/.../merge`) and can only be restored by re-runs of the same pull request.
|
||||||
|
- For `merge_group` triggered runs, the cache scope is limited to a temporary branch with a special prefix created to validate pull request changes, and won't be available on subsequent Merge Queue executions.
|
||||||
|
|
||||||
|
### Exclude content from Gradle User Home cache
|
||||||
|
|
||||||
|
As well as any wrapper distributions, the action will attempt to save and restore the `caches` and `notifications` directories from Gradle User Home.
|
||||||
|
|
||||||
|
Each build is different, and some builds produce more Gradle User Home content than others.
|
||||||
|
[Cache debugging ](#cache-debugging-and-analysis) can provide insight into which cache entries are the largest,
|
||||||
|
and the contents to be cached can be fine-tuned by including and excluding certain paths within the Gradle User Home.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# Cache downloaded JDKs in addition to the default directories.
|
||||||
|
gradle-home-cache-includes: |
|
||||||
|
caches
|
||||||
|
notifications
|
||||||
|
jdks
|
||||||
|
# Exclude the local build-cache and keyrings from the directories cached.
|
||||||
|
gradle-home-cache-excludes: |
|
||||||
|
caches/build-cache-1
|
||||||
|
caches/keyrings
|
||||||
|
```
|
||||||
|
|
||||||
|
You can specify any number of fixed paths or patterns to include or exclude.
|
||||||
|
File pattern support is documented at https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#patterns-to-match-file-paths.
|
||||||
|
|
||||||
|
### Disable local build-cache when remote build-cache is available
|
||||||
|
|
||||||
|
If you have a remote build-cache available for your build, then it is recommended to do the following:
|
||||||
|
- Enable [remote build-cache push](https://docs.gradle.org/current/userguide/build_cache.html#sec:build_cache_configure_use_cases) for your GitHub Actions builds
|
||||||
|
- Disable [local build-cache]() for your GitHub Actions build
|
||||||
|
|
||||||
|
As well as reducing the content that needs to be saved to the GitHub Actions cache,
|
||||||
|
this setup will ensure that your CI builds populate the remote cache and keep the cache entries fresh by reading these entries.
|
||||||
|
Local builds can then benefit from the remote cache.
|
||||||
|
|
||||||
|
## Debugging and Troubleshooting
|
||||||
|
|
||||||
|
To debug a failed job, it can be useful to run with [debug logging enabled](https://docs.github.com/en/actions/monitoring-and-troubleshooting-workflows/enabling-debug-logging).
|
||||||
|
You can enable debug logging either by:
|
||||||
|
1. Adding an `ACTIONS_STEP_DEBUG` variable to your repository configuration ([see here](https://docs.github.com/en/actions/monitoring-and-troubleshooting-workflows/enabling-debug-logging#enabling-step-debug-logging)).
|
||||||
|
2. By re-running a Job and checking the "Enable debug logging" box ([see here](https://github.blog/changelog/2022-05-24-github-actions-re-run-jobs-with-debug-logging/)).
|
||||||
|
|
||||||
|
### Increased logging from Gradle builds
|
||||||
|
|
||||||
|
When debug logging is enabled, this action will cause all builds to run with the `--info` and `--stacktrace` options.
|
||||||
|
This is done by inserting the relevant [Gradle properties](https://docs.gradle.org/current/userguide/build_environment.html#sec:gradle_configuration_properties)
|
||||||
|
at the top of the `${GRADLE_USER_HOME}/gradle.properties` file.
|
||||||
|
|
||||||
|
If the additional Gradle logging produced is problematic, you may opt out of this behavior by setting these properties manually in your project `gradle.properties` file:
|
||||||
|
|
||||||
|
```properties
|
||||||
|
# default lifecycle
|
||||||
|
org.gradle.logging.level=lifecycle
|
||||||
|
org.gradle.logging.stacktrace=internal
|
||||||
|
```
|
||||||
|
|
||||||
|
### Cache debugging and analysis
|
||||||
|
|
||||||
|
A report of all cache entries restored and saved is printed to the Job Summary when saving the cache entries.
|
||||||
|
This report can provide valuable insight into how much cache space is being used.
|
||||||
|
|
||||||
|
When debug logging is enabled, more detailed logging of cache operations is included in the GitHub actions log.
|
||||||
|
This includes a breakdown of the contents of the Gradle User Home directory, which may assist in cache optimization.
|
||||||
|
|
||||||
|
## Build reporting
|
||||||
|
|
||||||
|
The `setup-gradle` action collects information about any Gradle executions that occur in a workflow, including the root project,
|
||||||
|
requested tasks, build outcome, and any Build Scan link generated. Details of cache entries read and written are also collected.
|
||||||
|
These details are compiled into a Job Summary, which is visible in the GitHub Actions UI.
|
||||||
|
|
||||||
|
Generation of a Job Summary is enabled by default for all Jobs using The `setup-gradle` action. This feature can be configured
|
||||||
|
so that a Job Summary is never generated, or so that a Job Summary is only generated on build failure:
|
||||||
|
```yaml
|
||||||
|
add-job-summary: 'on-failure' # Valid values are 'always' (default), 'never', and 'on-failure'
|
||||||
|
```
|
||||||
|
|
||||||
|
### Adding Job Summary as a Pull Request comment
|
||||||
|
|
||||||
|
It is sometimes more convenient to view the results of a GitHub Actions Job directly from the Pull Request that triggered
|
||||||
|
the Job. For this purpose, you can configure the action so that Job Summary data is added as a Pull Request comment.
|
||||||
|
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name: CI
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
pull-requests: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
run-gradle-build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
add-job-summary-as-pr-comment: on-failure # Valid values are 'never' (default), 'always', and 'on-failure'
|
||||||
|
|
||||||
|
- run: ./gradlew build --scan
|
||||||
|
```
|
||||||
|
|
||||||
|
Note that to add a Pull Request comment, the workflow must be configured with the `pull-requests: write` permission.
|
||||||
|
|
||||||
|
|
||||||
|
### Build Scan® link as Step output
|
||||||
|
|
||||||
|
As well as reporting all [Build Scan](https://gradle.com/build-scans/) links in the Job Summary,
|
||||||
|
The `setup-gradle` action makes this link available as an output of any Step that executes Gradle.
|
||||||
|
|
||||||
|
The output name is `build-scan-url`. You can then use the build scan link in subsequent actions of your workflow.
|
||||||
|
|
||||||
|
### Saving arbitrary build outputs
|
||||||
|
|
||||||
|
By default, a GitHub Actions workflow using `setup-gradle` will record the log output and any Build Scan
|
||||||
|
links for your build, but any output files generated by the build will not be saved.
|
||||||
|
|
||||||
|
To save selected files from your build execution, you can use the core [Upload-Artifact](https://github.com/actions/upload-artifact) action.
|
||||||
|
For example:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
jobs:
|
||||||
|
gradle:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
|
||||||
|
- name: Run build with Gradle wrapper
|
||||||
|
run: ./gradlew build --scan
|
||||||
|
|
||||||
|
- name: Upload build reports
|
||||||
|
uses: actions/upload-artifact@v3
|
||||||
|
if: always()
|
||||||
|
with:
|
||||||
|
name: build-reports
|
||||||
|
path: build/reports/
|
||||||
|
```
|
||||||
|
|
||||||
|
### Use of custom init-scripts in Gradle User Home
|
||||||
|
|
||||||
|
Note that the action collects information about Gradle invocations via an [Initialization Script](https://docs.gradle.org/current/userguide/init_scripts.html#sec:using_an_init_script)
|
||||||
|
located at `USER_HOME/.gradle/init.d/gradle-actions.build-result-capture.init.gradle`.
|
||||||
|
|
||||||
|
If you are adding any custom init scripts to the `USER_HOME/.gradle/init.d` directory, it may be necessary to ensure these files are applied before `gradle-actions.build-result-capture.init.gradle`.
|
||||||
|
Since Gradle applies init scripts in alphabetical order, one way to ensure this is via file naming.
|
||||||
|
|
||||||
|
## Gradle Wrapper validation
|
||||||
|
|
||||||
|
By default, this action will perform the same wrapper validation as is performed by the dedicated
|
||||||
|
[wrapper-validation action](./wrapper-validation.md).
|
||||||
|
This means that invalid wrapper jars will be automatically detected when using `setup-gradle`.
|
||||||
|
|
||||||
|
If you do not want wrapper-validation to occur automatically, you can disable it:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
validate-wrappers: false
|
||||||
|
```
|
||||||
|
|
||||||
|
If your repository uses snapshot versions of the Gradle wrapper, such as nightly builds, then you'll need to
|
||||||
|
explicitly allow snapshot wrappers in wrapper validation.
|
||||||
|
These are not allowed by default.
|
||||||
|
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
validate-wrappers: true
|
||||||
|
allow-snapshot-wrappers: true
|
||||||
|
```
|
||||||
|
|
||||||
|
If you need more advanced configuration, then you're advised to continue using a separate workflow step
|
||||||
|
with `gradle/actions/wrapper-validation`.
|
||||||
|
|
||||||
|
## Support for GitHub Enterprise Server (GHES)
|
||||||
|
|
||||||
|
You can use the `setup-gradle` action on GitHub Enterprise Server, and benefit from the improved integration with Gradle. Depending on the version of GHES you are running, certain features may be limited:
|
||||||
|
- Build Scan links are captured and displayed in the GitHub Actions UI
|
||||||
|
- Easily run your build with different versions of Gradle
|
||||||
|
- Save/restore of Gradle User Home (requires GHES v3.5+ : GitHub Actions cache was introduced in GHES 3.5)
|
||||||
|
- Support for GitHub Actions Job Summary (requires GHES 3.6+ : GitHub Actions Job Summary support was introduced in GHES 3.6). In earlier versions of GHES, the build-results summary and caching report will be written to the workflow log, as part of the post-action step.
|
||||||
|
|
||||||
|
## GitHub Dependency Graph support
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> The simplest (and recommended) way to generate a dependency graph is via a separate workflow
|
||||||
|
> using `gradle/actions/dependency-submission`. This action will attempt to detect all dependencies used by your build
|
||||||
|
> without building and testing the project itself.
|
||||||
|
>
|
||||||
|
> See the [dependency-submission documentation](dependency-submission.md) for up-to-date documentation.
|
||||||
|
|
||||||
|
|
||||||
|
The `setup-gradle` action has support for submitting a [GitHub Dependency Graph](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph) snapshot via the [GitHub Dependency Submission API](https://docs.github.com/en/rest/dependency-graph/dependency-submission?apiVersion=2022-11-28).
|
||||||
|
|
||||||
|
The dependency graph snapshot is generated via integration with the [GitHub Dependency Graph Gradle Plugin](https://plugins.gradle.org/plugin/org.gradle.github-dependency-graph-gradle-plugin) and saved as a workflow artifact. The generated snapshot files can be submitted either in the same job or in a subsequent job (in the same or a dependent workflow).
|
||||||
|
|
||||||
|
The generated dependency graph snapshot reports all of the dependencies that were resolved during a build execution, and is used by GitHub to generate [Dependabot Alerts](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts) for vulnerable dependencies, as well as to populate the [Dependency Graph insights view](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/exploring-the-dependencies-of-a-repository#viewing-the-dependency-graph).
|
||||||
|
|
||||||
|
### Basic usage
|
||||||
|
|
||||||
|
You enable GitHub Dependency Graph support by setting the `dependency-graph` action parameter. Valid values are:
|
||||||
|
|
||||||
|
| Option | Behaviour |
|
||||||
|
| --- | --- |
|
||||||
|
| `disabled` | Do not generate a dependency graph for any build invocations.<p>This is the default. |
|
||||||
|
| `generate` | Generate a dependency graph snapshot for each build invocation. |
|
||||||
|
| `generate-and-submit` | Generate a dependency graph snapshot for each build invocation, and submit these via the Dependency Submission API on completion of the job. |
|
||||||
|
| `generate-and-upload` | Generate a dependency graph snapshot for each build invocation, saving it as a workflow artifact. |
|
||||||
|
| `download-and-submit` | Download any previously saved dependency graph snapshots, and submit them via the Dependency Submission API. This can be useful to submit [dependency graphs for pull requests submitted from repository forks](dependency-submission.md#usage-with-pull-requests-from-public-forked-repositories). |
|
||||||
|
|
||||||
|
Example of a CI workflow that generates and submits a dependency graph:
|
||||||
|
```yaml
|
||||||
|
name: CI build
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle to generate and submit dependency graphs
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-submit
|
||||||
|
- name: Run the usual CI build (dependency-graph will be generated and submitted post-job)
|
||||||
|
run: ./gradlew build
|
||||||
|
```
|
||||||
|
|
||||||
|
The `contents: write` permission is required to submit (but not generate) the dependency graph file.
|
||||||
|
Depending on [repository settings](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token), this permission may be available by default or may need to be explicitly enabled in the workflow file (as above).
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> The above configuration will work for workflows that run as a result of commits to a repository branch,
|
||||||
|
> but not when a workflow is triggered by a PR from a repository fork.
|
||||||
|
> This is because the `contents: write` permission is not available when executing a workflow
|
||||||
|
> for a PR submitted from a forked repository.
|
||||||
|
> For a configuration that supports this setup, see [Dependency Graphs for pull request workflows](dependency-submission.md#usage-with-pull-requests-from-public-forked-repositories).
|
||||||
|
|
||||||
|
### Making dependency graph failures cause Job failures
|
||||||
|
|
||||||
|
By default, if a failure is encountered when generating or submitting the dependency graph, the action will log the failure as a warning and continue.
|
||||||
|
This allows your workflow to be resilient to dependency graph failures, in case dependency graph production is a side-effect rather than the primary purpose of a workflow.
|
||||||
|
|
||||||
|
If instead, you have a workflow whose primary purpose is to generate and submit a dependency graph, it makes sense for this workflow to fail if the dependency
|
||||||
|
graph cannot be generated or submitted. You can enable this behavior with the `dependency-graph-continue-on-failure` parameter, which defaults to `true`.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# Ensure that the workflow Job will fail if the dependency graph cannot be submitted
|
||||||
|
- uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-submit
|
||||||
|
dependency-graph-continue-on-failure: false
|
||||||
|
```
|
||||||
|
|
||||||
|
### Using a custom plugin repository
|
||||||
|
|
||||||
|
By default, the action downloads the `github-dependency-graph-gradle-plugin` from the Gradle Plugin Portal (https://plugins.gradle.org). If your GitHub Actions environment does not have access to this URL, you can specify a custom plugin repository to use.
|
||||||
|
|
||||||
|
Do so by setting the `GRADLE_PLUGIN_REPOSITORY_URL` environment variable with your Gradle invocation.
|
||||||
|
The `GRADLE_PLUGIN_REPOSITORY_USERNAME` and `GRADLE_PLUGIN_REPOSITORY_PASSWORD` can be used when the plugin repository requires authentication.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle to generate and submit dependency graphs
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-submit
|
||||||
|
- name: Run a build, resolving the 'dependency-graph' plugin from the plugin portal proxy
|
||||||
|
run: ./gradlew build
|
||||||
|
env:
|
||||||
|
GRADLE_PLUGIN_REPOSITORY_URL: "https://gradle-plugins-proxy.mycorp.com"
|
||||||
|
|
||||||
|
# Set the following variables if your custom plugin repository requires authentication
|
||||||
|
# GRADLE_PLUGIN_REPOSITORY_USERNAME: "username"
|
||||||
|
# GRADLE_PLUGIN_REPOSITORY_PASSWORD: ${secrets.MY_REPOSITORY_PASSWORD}
|
||||||
|
```
|
||||||
|
|
||||||
|
### Choosing which Gradle invocations will generate a dependency graph
|
||||||
|
|
||||||
|
Once you enable the dependency graph support for a workflow job (via the `dependency-graph` parameter), dependencies will be collected and reported for all subsequent Gradle invocations.
|
||||||
|
If you have a Gradle build step that you want to exclude from dependency graph generation, you can set the `GITHUB_DEPENDENCY_GRAPH_ENABLED` environment variable to `false`.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-java@v4
|
||||||
|
with:
|
||||||
|
distribution: temurin
|
||||||
|
java-version: 17
|
||||||
|
|
||||||
|
- name: Setup Gradle to generate and submit dependency graphs
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate-and-submit
|
||||||
|
- name: Build the app, generating a graph of dependencies required
|
||||||
|
run: ./gradlew :my-app:assemble
|
||||||
|
- name: Run all checks, disabling dependency graph generation
|
||||||
|
run: ./gradlew check
|
||||||
|
env:
|
||||||
|
GITHUB_DEPENDENCY_GRAPH_ENABLED: false
|
||||||
|
```
|
||||||
|
|
||||||
|
### Filtering which Gradle Configurations contribute to the dependency graph
|
||||||
|
|
||||||
|
If you do not want the dependency graph to include every dependency configuration in every project in your build,
|
||||||
|
you can limit the dependency extraction to a subset of these.
|
||||||
|
|
||||||
|
See the documentation for [dependency-submission](dependency-submission.md) and the
|
||||||
|
[GitHub Dependency Graph Gradle Plugin](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#filtering-which-gradle-configurations-contribute-to-the-dependency-graph) for details.
|
||||||
|
|
||||||
|
### Gradle version compatibility
|
||||||
|
|
||||||
|
Dependency-graph generation is compatible with most versions of Gradle >= `5.2`, and is tested regularly against
|
||||||
|
Gradle versions `5.2.1`, `5.6.4`, `6.0.1`, `6.9.4`, `7.1.1` and `7.6.3`, as well as all patched versions of Gradle 8.x.
|
||||||
|
|
||||||
|
A known exception to this is that Gradle `7.0`, `7.0.1`, and `7.0.2` are not supported.
|
||||||
|
|
||||||
|
See [here](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#gradle-compatibility) for complete compatibility information.
|
||||||
|
|
||||||
|
### Reducing storage costs for saved dependency graph artifacts
|
||||||
|
|
||||||
|
When `generate` or `generate-and-submit` is used with the action, the dependency graph that is generated is stored as a workflow artifact.
|
||||||
|
By default, these artifacts are retained for 30 days (or as configured for the repository).
|
||||||
|
To reduce storage costs for these artifacts, you can set the `artifact-retention-days` value to a lower number.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Generate dependency graph, but only retain artifact for one day
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
dependency-graph: generate
|
||||||
|
artifact-retention-days: 1
|
||||||
|
```
|
||||||
|
|
||||||
|
# Develocity plugin injection
|
||||||
|
|
||||||
|
The `setup-gradle` action provides support for injecting and configuring the Develocity Gradle plugin into any Gradle build, without any modification to the project sources.
|
||||||
|
This is achieved via an init-script installed into Gradle User Home, which is enabled and parameterized via environment variables.
|
||||||
|
|
||||||
|
The same auto-injection behavior is available for the Common Custom User Data Gradle plugin, which enriches any build scans published with additional useful information.
|
||||||
|
|
||||||
|
## Enabling Develocity injection
|
||||||
|
|
||||||
|
To enable Develocity injection for your build, you must provide the required configuration via inputs.
|
||||||
|
|
||||||
|
Here's a minimal example:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
develocity-injection-enabled: true
|
||||||
|
develocity-url: https://develocity.your-server.com
|
||||||
|
develocity-plugin-version: 3.17.5
|
||||||
|
|
||||||
|
- name: Run a Gradle build with Develocity injection enabled
|
||||||
|
run: ./gradlew build
|
||||||
|
```
|
||||||
|
|
||||||
|
This configuration will automatically apply `v3.17.6` of the [Develocity Gradle plugin](https://docs.gradle.com/develocity/gradle-plugin/), and publish build scans to https://develocity.your-server.com.
|
||||||
|
|
||||||
|
This example assumes that the `develocity.your-server.com` server allows anonymous publishing of build scans.
|
||||||
|
In the likely scenario that your Develocity server requires authentication, you will also need to pass a valid [Develocity access key](https://docs.gradle.com/develocity/gradle-plugin/#via_environment_variable) taken from a secret:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
develocity-access-key: ${{ secrets.MY_DEVELOCITY_ACCESS_KEY }}
|
||||||
|
|
||||||
|
- name: Run a Gradle build with Develocity injection enabled
|
||||||
|
run: ./gradlew build
|
||||||
|
env:
|
||||||
|
DEVELOCITY_INJECTION_ENABLED: true
|
||||||
|
DEVELOCITY_URL: https://develocity.your-server.com
|
||||||
|
DEVELOCITY_PLUGIN_VERSION: 3.17
|
||||||
|
```
|
||||||
|
|
||||||
|
This access key will be used during the action execution to get a short-lived token and set it to the DEVELOCITY_ACCESS_KEY environment variable.
|
||||||
|
|
||||||
|
### Short-lived access tokens
|
||||||
|
Develocity access keys are long-lived, creating risks if they are leaked. To avoid this, users can use short-lived access tokens to authenticate with Develocity. Access tokens can be used wherever an access key would be used. Access tokens are only valid for the Develocity instance that created them.
|
||||||
|
If a short-lived token fails to be retrieved (for example, if the Develocity server version is lower than `2024.1`):
|
||||||
|
- if a `GRADLE_ENTERPRISE_ACCESS_KEY` env var has been set, we're falling back to it with a deprecation warning
|
||||||
|
- otherwise no access key env var will be set. In that case Develocity authenticated operations like build cache read/write and build scan publication will fail without failing the build.
|
||||||
|
For more information on short-lived tokens, see [Develocity API documentation](https://docs.gradle.com/develocity/api-manual/#short_lived_access_tokens).
|
||||||
|
|
||||||
|
## Configuring Develocity injection
|
||||||
|
|
||||||
|
The `init-script` supports several additional configuration parameters that you may find useful. All configuration options (required and optional) are detailed below:
|
||||||
|
|
||||||
|
| Variable | Required | Description |
|
||||||
|
|--------------------------------------| --- |-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||||
|
| develocity-injection-enabled | :white_check_mark: | enables Develocity injection |
|
||||||
|
| develocity-url | :white_check_mark: | the URL of the Develocity server |
|
||||||
|
| develocity-allow-untrusted-server | | allow communication with an untrusted server; set to _true_ if your Develocity instance is using a self-signed certificate |
|
||||||
|
| develocity-capture-file-fingerprints | | enables capturing the paths and content hashes of each individual input file |
|
||||||
|
| develocity-enforce-url | | enforce the configured Develocity URL over a URL configured in the project's build; set to _true_ to enforce publication of build scans to the configured Develocity URL |
|
||||||
|
| develocity-plugin-version | :white_check_mark: | the version of the [Develocity Gradle plugin](https://docs.gradle.com/develocity/gradle-plugin/) to apply |
|
||||||
|
| develocity-ccud-plugin-version | | the version of the [Common Custom User Data Gradle plugin](https://github.com/gradle/common-custom-user-data-gradle-plugin) to apply, if any |
|
||||||
|
| gradle-plugin-repository-url | | the URL of the repository to use when resolving the Develocity and CCUD plugins; the Gradle Plugin Portal is used by default |
|
||||||
|
| gradle-plugin-repository-username | | the username for the repository URL to use when resolving the Develocity and CCUD plugins |
|
||||||
|
| gradle-plugin-repository-password | | the password for the repository URL to use when resolving the Develocity and CCUD plugins; Consider using secrets to pass the value to this variable |
|
||||||
|
|
||||||
|
The input parameters can be expressed as environment variables following the relationships outlined in the table below:
|
||||||
|
|
||||||
|
| Input | Environment Variable |
|
||||||
|
|--------------------------------------|--------------------------------------|
|
||||||
|
| develocity-injection-enabled | DEVELOCITY_INJECTION_ENABLED |
|
||||||
|
| develocity-url | DEVELOCITY_URL |
|
||||||
|
| develocity-allow-untrusted-server | DEVELOCITY_ALLOW_UNTRUSTED_SERVER |
|
||||||
|
| develocity-capture-file-fingerprints | DEVELOCITY_CAPTURE_FILE_FINGERPRINTS |
|
||||||
|
| develocity-enforce-url | DEVELOCITY_ENFORCE_URL |
|
||||||
|
| develocity-plugin-version | DEVELOCITY_PLUGIN_VERSION |
|
||||||
|
| develocity-ccud-plugin-version | DEVELOCITY_CCUD_PLUGIN_VERSION |
|
||||||
|
| gradle-plugin-repository-url | GRADLE_PLUGIN_REPOSITORY_URL |
|
||||||
|
| gradle-plugin-repository-username | GRADLE_PLUGIN_REPOSITORY_USERNAME |
|
||||||
|
| gradle-plugin-repository-password | GRADLE_PLUGIN_REPOSITORY_PASSWORD |
|
||||||
|
|
||||||
|
|
||||||
|
Here's an example using the env vars:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
|
||||||
|
- name: Run a Gradle build with Develocity injection enabled with environment variables
|
||||||
|
run: ./gradlew build
|
||||||
|
env:
|
||||||
|
DEVELOCITY_INJECTION_ENABLED: true
|
||||||
|
DEVELOCITY_URL: https://develocity.your-server.com
|
||||||
|
DEVELOCITY_PLUGIN_VERSION: 3.17.6
|
||||||
|
```
|
||||||
|
|
||||||
|
## Publishing to scans.gradle.com
|
||||||
|
|
||||||
|
Develocity injection is designed to enable the publishing of build scans to a Develocity instance,
|
||||||
|
but is also useful for publishing to the public Build Scans instance (https://scans.gradle.com).
|
||||||
|
|
||||||
|
To publish to https://scans.gradle.com, you must specify in your workflow that you accept the [Gradle Terms of Use](https://gradle.com/help/legal-terms-of-use).
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- name: Setup Gradle to publish build scans
|
||||||
|
uses: gradle/actions/setup-gradle@v3
|
||||||
|
with:
|
||||||
|
build-scan-publish: true
|
||||||
|
build-scan-terms-of-use-url: "https://gradle.com/terms-of-service"
|
||||||
|
build-scan-terms-of-use-agree: "yes"
|
||||||
|
|
||||||
|
- name: Run a Gradle build - a build scan will be published automatically
|
||||||
|
run: ./gradlew build
|
||||||
|
```
|
||||||
|
|
||||||
|
# Dependency verification
|
||||||
|
|
||||||
|
Develocity injection, Build Scan publishing and Dependency Graph generation all work by applying external plugins to your build.
|
||||||
|
If you project has [dependency verification enabled](https://docs.gradle.org/current/userguide/dependency_verification.html#sec:signature-verification),
|
||||||
|
then you'll need to update your verification metadata to trust these plugins.
|
||||||
|
|
||||||
|
Each of the plugins is signed by Gradle, and you can simply add the following snippet to your `dependency-verificaton.xml` file:
|
||||||
|
|
||||||
|
```xml
|
||||||
|
<trusted-keys>
|
||||||
|
<trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671">
|
||||||
|
<trusting group="com.gradle"/>
|
||||||
|
<trusting group="org.gradle"/>
|
||||||
|
</trusted-key>
|
||||||
|
</trusted-keys>
|
||||||
|
```
|
||||||
|
|
||||||
116
docs/wrapper-validation.md
Normal file
116
docs/wrapper-validation.md
Normal file
@@ -0,0 +1,116 @@
|
|||||||
|
# Gradle Wrapper Validation Action
|
||||||
|
|
||||||
|
This action validates the checksums of _all_ [Gradle Wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html) JAR files present in the repository and fails if any unknown Gradle Wrapper JAR files are found.
|
||||||
|
|
||||||
|
The action should be run in the root of the repository, as it will recursively search for any files named `gradle-wrapper.jar`.
|
||||||
|
|
||||||
|
The `setup-gradle` action will perform wrapper validation on each execution. If you are using `setup-gradle` in your
|
||||||
|
workflows, it is unlikely that you will need to use this action.
|
||||||
|
|
||||||
|
## The Gradle Wrapper Problem in Open Source
|
||||||
|
|
||||||
|
The `gradle-wrapper.jar` is a binary blob of executable code that is checked into nearly
|
||||||
|
[2.8 Million GitHub Repositories](https://github.com/search?l=&q=filename%3Agradle-wrapper.jar&type=Code).
|
||||||
|
|
||||||
|
Searching across GitHub you can find many pull requests (PRs) with helpful titles like 'Update to Gradle xxx'.
|
||||||
|
Many of these PRs are contributed by individuals outside of the organization maintaining the project.
|
||||||
|
|
||||||
|
Many maintainers are incredibly grateful for these kinds of contributions as it takes an item off of their backlog.
|
||||||
|
We assume that most maintainers do not consider the security implications of accepting the Gradle Wrapper binary from external contributors.
|
||||||
|
There is a certain amount of blind trust open source maintainers have.
|
||||||
|
Further compounding the issue is that maintainers are most often greeted in these PRs with a diff to the `gradle-wrapper.jar` that looks like this.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
A fairly simple social engineering supply chain attack against open source would be contribute a helpful “Updated to Gradle xxx” PR that contains malicious code hidden inside this binary JAR.
|
||||||
|
A malicious `gradle-wrapper.jar` could execute, download, or install arbitrary code while otherwise behaving like a completely normal `gradle-wrapper.jar`.
|
||||||
|
|
||||||
|
## Solution
|
||||||
|
|
||||||
|
We have created a simple GitHub Action that can be applied to any GitHub repository.
|
||||||
|
This GitHub Action will do one simple task:
|
||||||
|
verify that any and all `gradle-wrapper.jar` files in the repository match the SHA-256 checksums of any of our official releases.
|
||||||
|
|
||||||
|
If any are found that do not match the SHA-256 checksums of our official releases, the action will fail.
|
||||||
|
|
||||||
|
Additionally, the action will find and SHA-256 hash all
|
||||||
|
[homoglyph](https://en.wikipedia.org/wiki/Homoglyph)
|
||||||
|
variants of files named `gradle-wrapper.jar`,
|
||||||
|
for example a file named `gradlе-wrapper.jar` (which uses a Cyrillic `е` instead of `e`).
|
||||||
|
The goal is to prevent homoglyph attacks which may be very difficult to spot in a GitHub diff.
|
||||||
|
We created an example [Homoglyph attack PR here](https://github.com/JLLeitschuh/playframework/pull/1/files).
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
|
||||||
|
### Add to an existing Workflow
|
||||||
|
|
||||||
|
Simply add this action to your workflow **after** having checked out your source tree and **before** running any Gradle build:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
uses: gradle/actions/wrapper-validation@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
This action step should precede any step using `gradle/gradle-build-action` or `gradle/actions/setup-gradle`.
|
||||||
|
|
||||||
|
### Add a new dedicated Workflow
|
||||||
|
|
||||||
|
Here's a sample complete workflow you can add to your repositories:
|
||||||
|
|
||||||
|
**`.github/workflows/gradle-wrapper-validation.yml`**
|
||||||
|
```yaml
|
||||||
|
name: "Validate Gradle Wrapper"
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
validation:
|
||||||
|
name: "Validation"
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: gradle/actions/wrapper-validation@v3
|
||||||
|
```
|
||||||
|
|
||||||
|
## Contributing to an external GitHub Repository
|
||||||
|
|
||||||
|
Since [GitHub Actions](https://github.com/features/actions)
|
||||||
|
are completely free for open source projects and are automatically enabled on almost all projects,
|
||||||
|
adding this check to a project's build is as simple as contributing a PR.
|
||||||
|
Enabling the check requires no overhead on behalf of the project maintainer beyond merging the action.
|
||||||
|
|
||||||
|
You can add this action to your favorite Gradle based project without checking out their source locally via the
|
||||||
|
GitHub Web UI thanks to the 'Create new file' button.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Simply add a new file named `.github/workflows/gradle-wrapper-validation.yml` with the contents mentioned above.
|
||||||
|
|
||||||
|
We recommend the message commit contents of:
|
||||||
|
- Title: `Official Gradle Wrapper Validation Action`
|
||||||
|
- Body (at minimum): `See: https://github.com/gradle/actions/wrapper-validation`
|
||||||
|
|
||||||
|
From there, you can easily follow the rest of the prompts to create a Pull Request against the project.
|
||||||
|
|
||||||
|
## Validation Failures
|
||||||
|
|
||||||
|
A wrapper jar can fail validation for a few reasons:
|
||||||
|
1. The wrapper is from a snapshot build of Gradle (nightly or release nightly) and you have not set `allow-snapshots`
|
||||||
|
or `allow-snapshot-wrappers` to `true`.
|
||||||
|
2. The wrapper jar is from a version of Gradle with an unverifiable wrapper jar (see below).
|
||||||
|
3. The wrapper jar was not published by Gradle, and could be compromised.
|
||||||
|
|
||||||
|
If this GitHub action fails because a `gradle-wrapper.jar` was not published by Gradle,
|
||||||
|
we highly recommend that you reach out to us at [security@gradle.com](mailto:security@gradle.com).
|
||||||
|
|
||||||
|
#### Unverifiable Wrapper Jars
|
||||||
|
Wrapper Jars generated by Gradle versions `3.3` to `4.0` are not verifiable because those files were dynamically generated by Gradle in a non-reproducible way. It's not possible to verify the `gradle-wrapper.jar` for those versions are legitimate using a hash comparison. If you have a validation failure, you should try to determine if the `gradle-wrapper.jar` was generated by one of these versions before running the build.
|
||||||
|
|
||||||
|
- If the Gradle version in `gradle-wrapper.properties` is outside of this range, you can regenerate the `gradle-wrapper.jar` by running `./gradlew wrapper`. This will generate a new, verifiable wrapper jar.
|
||||||
|
- If you need to run your build with a version of Gradle between 3.3 and 4.0, you can use a newer version of Gradle to generate the `gradle-wrapper.jar`.
|
||||||
|
|
||||||
|
## Resources
|
||||||
|
|
||||||
|
To learn more about verifying the Gradle Wrapper JAR locally, see our
|
||||||
|
[guide on the topic](https://docs.gradle.org/current/userguide/gradle_wrapper.html#wrapper_checksum_verification).
|
||||||
@@ -1,701 +1,34 @@
|
|||||||
# Configure Gradle for GitHub Actions workflows
|
## The `setup-gradle` action
|
||||||
|
|
||||||
This GitHub Action can be used to configure Gradle for optimal execution on any platform supported by GitHub Actions.
|
The `setup-gradle` action can be used to configure Gradle for optimal execution on any platform supported by GitHub Actions.
|
||||||
|
|
||||||
## Why use the `setup-gradle` action?
|
This replaces the previous `gradle/gradle-build-action`, which now delegates to this implementation.
|
||||||
|
|
||||||
It is possible to directly invoke Gradle in your workflow, and the `actions/setup-java@v4` action provides a simple way to cache Gradle dependencies.
|
The recommended way to execute any Gradle build is with the help of the [Gradle Wrapper](https://docs.gradle.org/current/userguide/gradle_wrapper.html), and the examples assume that the Gradle Wrapper has been configured for the project. See [this example](../docs/setup-gradle.md#build-with-a-specific-gradle-version) if your project doesn't use the Gradle Wrapper.
|
||||||
|
|
||||||
However, the `setup-gradle` action offers a number of advantages over this approach:
|
|
||||||
|
|
||||||
- Easily [configure your workflow to use a specific version of Gradle](#choose-a-specific-gradle-version) using the `gradle-version` parameter. Gradle distributions are automatically downloaded and cached.
|
|
||||||
- More sophisticated and more efficient caching of Gradle User Home between invocations, compared to `setup-java` and most custom configurations using `actions/cache`. [More details below](#caching-build-state-between-jobs).
|
|
||||||
- Detailed reporting of cache usage and cache configuration options allow you to [optimize the use of the GitHub actions cache](#optimizing-cache-effectiveness).
|
|
||||||
- [Generate and Submit a GitHub Dependency Graph](#github-dependency-graph-support) for your project, enabling Dependabot security alerts.
|
|
||||||
- [Automatic capture of Build Scan® links](#build-reporting) from the build, making these easier to locate for workflow run.
|
|
||||||
|
|
||||||
The `setup-gradle` action is designed to provide these benefits with minimal configuration.
|
|
||||||
These features work both when Gradle is executed via `setup-gradle` and for any Gradle execution in subsequent steps.
|
|
||||||
|
|
||||||
## General usage
|
|
||||||
|
|
||||||
The `setup-gradle` action works by configuring environment variables and by adding a set of Gradle init-scripts to the Gradle User Home. These will apply to all Gradle executions on the runner, no matter how Gradle is invoked.
|
|
||||||
This means that if you have an existing workflow that executes Gradle with a `run` step, you can add an initial "Setup Gradle" Step to benefit from caching, build-scan capture and other features of this action.
|
|
||||||
|
|
||||||
|
### Example usage
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
name: Run Gradle on every push
|
name: Build
|
||||||
on: push
|
|
||||||
jobs:
|
|
||||||
gradle:
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: [ubuntu-latest, macos-latest, windows-latest]
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
distribution: temurin
|
|
||||||
java-version: 11
|
|
||||||
|
|
||||||
- name: Setup Gradle
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
|
|
||||||
- name: Execute Gradle build
|
|
||||||
run: ./gradlew build
|
|
||||||
```
|
|
||||||
|
|
||||||
## Choose a specific Gradle version
|
|
||||||
|
|
||||||
The `setup-gradle` action can download and install a specified Gradle version, adding this installed version to the PATH.
|
|
||||||
Downloaded Gradle versions are stored in the GitHub Actions cache, to avoid requiring downloading again later.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
- uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
gradle-version: 6.5
|
|
||||||
```
|
|
||||||
|
|
||||||
The `gradle-version` parameter can be set to any valid Gradle version.
|
|
||||||
|
|
||||||
Moreover, you can use the following aliases:
|
|
||||||
|
|
||||||
| Alias | Selects |
|
|
||||||
| --- |---|
|
|
||||||
| `wrapper` | The Gradle wrapper's version (default, useful for matrix builds) |
|
|
||||||
| `current` | The current [stable release](https://gradle.org/install/) |
|
|
||||||
| `release-candidate` | The current [release candidate](https://gradle.org/release-candidate/) if any, otherwise fallback to `current` |
|
|
||||||
| `nightly` | The latest [nightly](https://gradle.org/nightly/), fails if none. |
|
|
||||||
| `release-nightly` | The latest [release nightly](https://gradle.org/release-nightly/), fails if none. |
|
|
||||||
|
|
||||||
This can be handy to automatically verify your build works with the latest release candidate of Gradle:
|
|
||||||
|
|
||||||
The actual Gradle version used is available as an action output: `gradle-version`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Test latest Gradle RC
|
|
||||||
on:
|
|
||||||
schedule:
|
|
||||||
- cron: 0 0 * * * # daily
|
|
||||||
jobs:
|
|
||||||
gradle-rc:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- uses: actions/setup-java@v4
|
|
||||||
with:
|
|
||||||
distribution: temurin
|
|
||||||
java-version: 11
|
|
||||||
- uses: gradle/actions/setup-gradle@v3
|
|
||||||
id: setup-gradle
|
|
||||||
with:
|
|
||||||
gradle-version: release-candidate
|
|
||||||
- run: gradle build --dry-run # just test build configuration
|
|
||||||
- run: echo "The release-candidate version was ${{ steps.setup-gradle.outputs.gradle-version }}"
|
|
||||||
```
|
|
||||||
|
|
||||||
## Caching build state between Jobs
|
|
||||||
|
|
||||||
The `setup-gradle` action will use the GitHub Actions cache to save and restore reusable state that may be speed up a subsequent build invocation. This includes most content that is downloaded from the internet as part of a build, as well as expensive to create content like compiled build scripts, transformed Jar files, etc.
|
|
||||||
|
|
||||||
The state that is cached includes:
|
|
||||||
- Any distributions downloaded to satisfy a `gradle-version` parameter ;
|
|
||||||
- A subset of the Gradle User Home directory, including downloaded dependencies, wrapper distributions, and the local build cache ;
|
|
||||||
|
|
||||||
To reduce the space required for caching, this action makes a best effort to reduce duplication in cache entries.
|
|
||||||
|
|
||||||
State will be restored from the cache during the first `setup-gradle` step for any workflow job, and cache entries will be written back to the cache at the end of the job, after all Gradle executions have completed.
|
|
||||||
|
|
||||||
### Disabling caching
|
|
||||||
|
|
||||||
Caching is enabled by default. You can disable caching for the action as follows:
|
|
||||||
```yaml
|
|
||||||
cache-disabled: true
|
|
||||||
```
|
|
||||||
|
|
||||||
### Using the cache read-only
|
|
||||||
|
|
||||||
By default, The `setup-gradle` action will only write to the cache from Jobs on the default (`main`/`master`) branch.
|
|
||||||
Jobs on other branches will read entries from the cache but will not write updated entries.
|
|
||||||
See [Optimizing cache effectiveness](#select-which-branches-should-write-to-the-cache) for a more detailed explanation.
|
|
||||||
|
|
||||||
In some circumstances it makes sense to change this default, and to configure a workflow Job to read existing cache entries but not to write changes back.
|
|
||||||
|
|
||||||
You can configure read-only caching for `setup-gradle` as follows:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cache-read-only: true
|
|
||||||
```
|
|
||||||
|
|
||||||
You can also configure read-only caching only for certain branches:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# Only write to the cache for builds on the 'main' and 'release' branches. (Default is 'main' only.)
|
|
||||||
# Builds on other branches will only read existing entries from the cache.
|
|
||||||
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/release' }}
|
|
||||||
```
|
|
||||||
|
|
||||||
### Using the cache write-only
|
|
||||||
|
|
||||||
In certain circumstances it may be desirable to start with a clean Gradle User Home state, but to save that state at the end of a workflow Job:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cache-write-only: true
|
|
||||||
```
|
|
||||||
|
|
||||||
### Overwriting an existing Gradle User Home
|
|
||||||
|
|
||||||
When the action detects that the Gradle User Home caches directory already exists (`~/.gradle/caches`), then by default it will not overwrite the existing content of this directory.
|
|
||||||
This can occur when a prior action initializes this directory, or when using a self-hosted runner that retains this directory between uses.
|
|
||||||
|
|
||||||
In this case the Job Summary will display a message like:
|
|
||||||
> Caching for Gradle actions was disabled due to pre-existing Gradle User Home
|
|
||||||
|
|
||||||
If you want override the default and have The `setup-gradle` action caches overwrite existing content in the Gradle User Home, you can set the `cache-overwrite-existing` parameter to 'true':
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
cache-overwrite-existing: true
|
|
||||||
```
|
|
||||||
|
|
||||||
### Saving configuration-cache data
|
|
||||||
|
|
||||||
When Gradle is executed with the [configuration-cache](https://docs.gradle.org/current/userguide/configuration_cache.html) enabled, the configuration-cache data is stored
|
|
||||||
in the project directory, at `<project-dir>/.gradle/configuration-cache`. Due to the way the configuration-cache works, [this file may contain stored credentials and other
|
|
||||||
secrets](https://docs.gradle.org/release-nightly/userguide/configuration_cache.html#config_cache:secrets), and this data needs to be encrypted in order to be safely stored in the GitHub Actions cache.
|
|
||||||
|
|
||||||
In order to benefit from configuration caching in your GitHub Actions workflow, you must:
|
|
||||||
- Execute your build with Gradle 8.6 or newer. This can be achieved directly, or via the Gradle Wrapper.
|
|
||||||
- Enable the configuration cache for your build.
|
|
||||||
- Generate a [valid Gradle encryption key](https://docs.gradle.org/8.6/userguide/configuration_cache.html#config_cache:secrets:configuring_encryption_key) and save it as a [GitHub Actions secret](https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions).
|
|
||||||
- Provide the secret key via the `cache-encryption-key` action parameter.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
gradle-with-configuration-cache:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
gradle-version: 8.6
|
|
||||||
cache-encryption-key: ${{ secrets.GradleEncryptionKey }}
|
|
||||||
- run: gradle build --configuration-cache
|
|
||||||
```
|
|
||||||
|
|
||||||
### Incompatibility with other caching mechanisms
|
|
||||||
|
|
||||||
When using `setup-gradle` we recommend that you avoid using other mechanisms to save and restore the Gradle User Home.
|
|
||||||
|
|
||||||
Specifically:
|
|
||||||
- Avoid using `actions/cache` configured to cache the Gradle User Home, [as described in this example](https://github.com/actions/cache/blob/main/examples.md#java---gradle).
|
|
||||||
- Avoid using `actions/setup-java` with the `cache: gradle` option, [as described here](https://github.com/actions/setup-java#caching-gradle-dependencies).
|
|
||||||
|
|
||||||
Using either of these mechanisms may interfere with the caching provided by this action. If you choose to use a different mechanism to save and restore the Gradle User Home, you should disable the caching provided by this action, as described above.
|
|
||||||
|
|
||||||
## How Gradle User Home caching works
|
|
||||||
|
|
||||||
### Properties of the GitHub Actions cache
|
|
||||||
|
|
||||||
The GitHub Actions cache has some properties that present problems for efficient caching of the Gradle User Home.
|
|
||||||
- Immutable entries: once a cache entry is written for a key, it cannot be overwritten or changed.
|
|
||||||
- Branch scope: cache entries written for a Git branch are not visible from actions running against different branches. Entries written for the default branch are visible to all. https://docs.github.com/en/actions/using-workflows/caching-dependencies-to-speed-up-workflows#restrictions-for-accessing-a-cache
|
|
||||||
- Restore keys: if no exact match is found, a set of partial keys can be provided that will match by cache key prefix. https://docs.github.com/en/actions/using-workflows/caching-dependencies-to-speed-up-workflows#matching-a-cache-key
|
|
||||||
|
|
||||||
Each of these properties has influenced the design and implementation of the caching in `setup-gradle`, as described below.
|
|
||||||
|
|
||||||
### Which content is cached
|
|
||||||
|
|
||||||
Using experiments and observations, we have attempted to identify which Gradle User Home content is worth saving and restoring between build invocations. We considered both the respective size of the content and the impact this content has on build times. As well as the obvious candidates like downloaded dependencies, we saw that compiled build scripts, transformed Jar files and other content can also have a significant impact.
|
|
||||||
|
|
||||||
In the end, we opted to save and restore as much content as is practical, including:
|
|
||||||
- `caches/<version>/generated-gradle-jars`: These files are generated on first use of a particular Gradle version, and are expensive to recreate
|
|
||||||
- `caches/<version>/kotlin-dsl` and `caches/<version>/scripts`: These are the compiled build scripts. The Kotlin ones in particular can benefit from caching.
|
|
||||||
- `caches/modules-2`: The downloaded dependencies
|
|
||||||
- `caches/transforms-3`: The results of artifact transforms
|
|
||||||
- `caches/jars-9`: Jar files that have been processed/instrumented by Gradle
|
|
||||||
- `caches/build-cache-1`: The local build cache
|
|
||||||
|
|
||||||
In certain cases a particular section of Gradle User Home will be too large to make caching effective. In these cases, particular subdirectories can be excluded from caching. See [Exclude content from Gradle User Home cache](#exclude-content-from-gradle-user-home-cache).
|
|
||||||
|
|
||||||
### Cache keys
|
|
||||||
|
|
||||||
The actual content of the Gradle User Home after a build is the result of many factors, including:
|
|
||||||
- Core Gradle build files (`settings.gradle[.kts]`, `build.gradle[.kts]`, `gradle.properties`)
|
|
||||||
- Associated Gradle configuration files (`gradle-wrapper.properties`, `dependencies.toml`, etc)
|
|
||||||
- The entire content of `buildSrc` or any included builds that provide plugins.
|
|
||||||
- The entire content of the repository, in the case of the local build cache.
|
|
||||||
- The actual build command that was invoked, including system properties and environment variables.
|
|
||||||
|
|
||||||
For this reason, it's very difficult to create a cache key that will deterministically map to a saved Gradle User Home state. So instead of trying to reliably hash all of these inputs to generate a cache key, the Gradle User Home cache key is based on the currently executing Job and the current commit hash for the repository.
|
|
||||||
|
|
||||||
The Gradle User Home cache key is composed of:
|
|
||||||
- The current operating system (`RUNNER_OS`)
|
|
||||||
- The Job id
|
|
||||||
- A hash of the Job matrix parameters and the workflow name
|
|
||||||
- The git SHA for the latest commit
|
|
||||||
|
|
||||||
Specifically, the cache key is: `${cache-protocol}-gradle|${runner-os}|${job-id}[${hash-of-job-matrix-and-workflow-name}]-${git-sha}`
|
|
||||||
|
|
||||||
As such, the cache key is likely to change on each subsequent run of GitHub actions.
|
|
||||||
This allows the most recent state to always be available in the GitHub actions cache.
|
|
||||||
|
|
||||||
### Finding a matching cache entry
|
|
||||||
|
|
||||||
In most cases, no exact match will exist for the cache key. Instead, the Gradle User Home will be restored for the closest matching cache entry, using a set of "restore keys". The entries will be matched with the following precedence:
|
|
||||||
- An exact match on OS, job id, workflow name, matrix and Git SHA
|
|
||||||
- The most recent entry saved for the same OS, job id, workflow name and matrix values
|
|
||||||
- The most recent entry saved for the same OS and job id
|
|
||||||
- The most recent entry saved for the same OS
|
|
||||||
|
|
||||||
Due to branch scoping of cache entries, the above match will be first performed for entries from the same branch, and then for the default ('main') branch.
|
|
||||||
|
|
||||||
After the Job is complete, the current Gradle User Home state will be collected and written as a new cache entry with the complete cache key. Old entries will be expunged from the GitHub Actions cache on a least-recently-used basis.
|
|
||||||
|
|
||||||
Note that while effective, this mechanism is not inherently efficient. It requires the entire Gradle User Home directory to be stored separately for each branch, for every OS+Job+Matrix combination. In addition, a new cache entry to be written on every GitHub Actions run.
|
|
||||||
|
|
||||||
This inefficiency is effectively mitigated by [Deduplication of Gradle User Home cache entries](#deduplication-of-gradle-user-home-cache-entries), and can be further optimized for a workflow using the techniques described in [Optimizing cache effectiveness](#optimizing-cache-effectiveness).
|
|
||||||
|
|
||||||
### Deduplication of Gradle User Home cache entries
|
|
||||||
|
|
||||||
To reduce duplication between cache entries, certain artifacts in Gradle User Home are extracted and cached independently based on their identity. This allows each Gradle User Home cache entry to be relatively small, sharing common elements between them without duplication.
|
|
||||||
|
|
||||||
Artifacts that are cached independently include:
|
|
||||||
- Downloaded dependencies
|
|
||||||
- Downloaded wrapper distributions
|
|
||||||
- Generated Gradle API jars
|
|
||||||
- Downloaded Java Toolchains
|
|
||||||
|
|
||||||
For example, this means that all jobs executing a particular version of the Gradle wrapper will share a single common entry for this wrapper distribution and one for each of the generated Gradle API jars.
|
|
||||||
|
|
||||||
### Stopping the Gradle daemon
|
|
||||||
|
|
||||||
By default, the action will stop all running Gradle daemons in the post-action step, prior to saving the Gradle User Home state.
|
|
||||||
This allows for any Gradle User Home cleanup to occur, and avoid file-locking issues on Windows.
|
|
||||||
|
|
||||||
If caching is disabled or the cache is in read-only mode, the daemon will not be stopped and will continue running after the job is completed.
|
|
||||||
|
|
||||||
## Optimizing cache effectiveness
|
|
||||||
|
|
||||||
Cache storage space for GitHub actions is limited, and writing new cache entries can trigger the deletion of existing entries.
|
|
||||||
Eviction of shared cache entries can reduce cache effectiveness, slowing down your `setup-gradle` steps.
|
|
||||||
|
|
||||||
There are a number of actions you can take if your cache use is less effective due to entry eviction.
|
|
||||||
|
|
||||||
At the end of a Job, The `setup-gradle` action will write a summary of the Gradle builds executed, together with a detailed report of the cache entries that were read and written during the Job. This report can provide valuable insights that may help to determine the right way to optimize the cache usage for your workflow.
|
|
||||||
|
|
||||||
### Select which jobs should write to the cache
|
|
||||||
|
|
||||||
Consider a workflow that first runs a Job "compile-and-unit-test" to compile the code and run some basic unit tests, which is followed by a matrix of parallel "integration-test" jobs that each run a set of integration tests for the repository. Each "integration test" Job requires all of the dependencies required by "compile-and-unit-test", and possibly one or 2 additional dependencies.
|
|
||||||
|
|
||||||
By default, a new cache entry will be written on completion of each integration test job. If no additional dependencies were downloaded then this cache entry will share the "dependencies" entry with the "compile-and-unit-test" job, but if a single dependency was downloaded then an entire new "dependencies" entry would be written. (The `setup-gradle` action does not _yet_ support a layered cache that could do this more efficiently). If each of these "integration-test" entries with their different "dependencies" entries is too large, then it could result in other important entries being evicted from the GitHub Actions cache.
|
|
||||||
|
|
||||||
There are some techniques that can be used to avoid/mitigate this issue:
|
|
||||||
- Configure the "integration-test" jobs with `cache-read-only: true`, meaning that the Job will use the entry written by the "compile-and-unit-test" job. This will avoid the overhead of cache entries for each of these jobs, at the expense of re-downloading any additional dependencies required by "integration-test".
|
|
||||||
- Add an additional step to the "compile-and-unit-test" job which downloads all dependencies required by the integration-test jobs but does not execute the tests. This will allow the "dependencies" entry for "compile-and-unit-test" to be shared among all cache entries for "integration-test". The resulting "integration-test" entries should be much smaller, reducing the potential for eviction.
|
|
||||||
- Combine the above 2 techniques, so that no cache entry is written by "integration-test" jobs, but all required dependencies are already present from the restored "compile-and-unit-test" entry.
|
|
||||||
|
|
||||||
### Select which branches should write to the cache
|
|
||||||
|
|
||||||
GitHub cache entries are not shared between builds on different branches.
|
|
||||||
Workflow runs can restore caches created in either the current branch or the default branch (usually main).
|
|
||||||
This means that each branch will have it's own Gradle User Home cache scope, and will not benefit from cache entries written for other (non-default) branches.
|
|
||||||
|
|
||||||
By default, The `setup-gradle` action will only _write_ to the cache for builds run on the default (`master`/`main`) branch.
|
|
||||||
Jobs run on other branches will only read from the cache. In most cases, this is the desired behavior.
|
|
||||||
This is because Jobs run on other branches will benefit from the cache Gradle User Home from `main`,
|
|
||||||
without writing private cache entries that which could lead to evicting these shared entries.
|
|
||||||
|
|
||||||
If you have other long-lived development branches that would benefit from writing to the cache,
|
|
||||||
you can configure this by disabling the `cache-read-only` action parameter for these branches.
|
|
||||||
See [Using the cache read-only](#using-the-cache-read-only) for more details.
|
|
||||||
|
|
||||||
Note there are some cases where writing cache entries is typically unhelpful (these are disabled by default):
|
|
||||||
- For `pull_request` triggered runs, the cache scope is limited to the merge ref (`refs/pull/.../merge`) and can only be restored by re-runs of the same pull request.
|
|
||||||
- For `merge_group` triggered runs, the cache scope is limited to a temporary branch with a special prefix created to validate pull request changes, and won't be available on subsequent Merge Queue executions.
|
|
||||||
|
|
||||||
### Exclude content from Gradle User Home cache
|
|
||||||
|
|
||||||
As well as any wrapper distributions, the action will attempt to save and restore the `caches` and `notifications` directories from Gradle User Home.
|
|
||||||
|
|
||||||
Each build is different, and some builds produce more Gradle User Home content than others.
|
|
||||||
[Cache debugging ](#cache-debugging-and-analysis) can provide insight into which cache entries are the largest,
|
|
||||||
and the contents to be cached can be fine tuned by including and excluding certain paths within Gradle User Home.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# Cache downloaded JDKs in addition to the default directories.
|
|
||||||
gradle-home-cache-includes: |
|
|
||||||
caches
|
|
||||||
notifications
|
|
||||||
jdks
|
|
||||||
# Exclude the local build-cache and keyrings from the directories cached.
|
|
||||||
gradle-home-cache-excludes: |
|
|
||||||
caches/build-cache-1
|
|
||||||
caches/keyrings
|
|
||||||
```
|
|
||||||
|
|
||||||
You can specify any number of fixed paths or patterns to include or exclude.
|
|
||||||
File pattern support is documented at https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#patterns-to-match-file-paths.
|
|
||||||
|
|
||||||
### Remove unused files from Gradle User Home before saving to cache
|
|
||||||
|
|
||||||
The Gradle User Home directory has a tendency to grow over time. When you switch to a new Gradle wrapper version or upgrade a dependency version
|
|
||||||
the old files are not automatically and immediately removed. While this can make sense in a local environment, in a GitHub Actions environment
|
|
||||||
it can lead to ever-larger Gradle User Home cache entries being saved and restored.
|
|
||||||
|
|
||||||
In order to avoid this situation, The `setup-gradle` action supports the `gradle-home-cache-cleanup` parameter.
|
|
||||||
When enabled, this feature will attempt to delete any files in the Gradle User Home that were not used by Gradle during the GitHub Actions workflow,
|
|
||||||
prior to saving the Gradle User Home to the GitHub Actions cache.
|
|
||||||
|
|
||||||
Gradle Home cache cleanup is considered experimental and is disabled by default. You can enable this feature for the action as follows:
|
|
||||||
```yaml
|
|
||||||
gradle-home-cache-cleanup: true
|
|
||||||
```
|
|
||||||
## Debugging and Troubleshooting
|
|
||||||
|
|
||||||
In order to debug a failed job, it can be useful to run with [debug logging enabled](https://docs.github.com/en/actions/monitoring-and-troubleshooting-workflows/enabling-debug-logging).
|
|
||||||
You can enable debug logging either by adding an `ACTIONS_STEP_DEBUG` variable to your repository configuration, or by re-running a Job and checking the "Enable debug logging" box.
|
|
||||||
|
|
||||||
### Increased logging from Gradle builds
|
|
||||||
|
|
||||||
When debug logging is enabled, this action will cause all builds to run with the `--info` and `--stacktrace` options.
|
|
||||||
This is done by inserting the relevant [Gradle properties](https://docs.gradle.org/current/userguide/build_environment.html#sec:gradle_configuration_properties)
|
|
||||||
at the top of the `${GRADLE_USER_HOME}/gradle.properties` file.
|
|
||||||
|
|
||||||
If the additional Gradle logging produced is problematic, you may opt-out of this behaviour by setting these properties manually in your project `gradle.properties` file:
|
|
||||||
|
|
||||||
```properties
|
|
||||||
# default lifecycle
|
|
||||||
org.gradle.logging.level=lifecycle
|
|
||||||
org.gradle.logging.stacktrace=internal
|
|
||||||
```
|
|
||||||
|
|
||||||
### Cache debugging and analysis
|
|
||||||
|
|
||||||
A report of all cache entries restored and saved is printed to the Job Summary when saving the cache entries.
|
|
||||||
This report can provide valuable insight into how much cache space is being used.
|
|
||||||
|
|
||||||
When debug logging is enabled, more detailed logging of cache operations is included in the GitHub actions log.
|
|
||||||
This includes a breakdown of the contents of the Gradle User Home directory, which may assist in cache optimization.
|
|
||||||
|
|
||||||
## Build reporting
|
|
||||||
|
|
||||||
The `setup-gradle` action collects information about any Gradle executions that occur in a workflow, including the root project,
|
|
||||||
requested tasks, build outcome and any Build Scan link generated. Details of cache entries read and written are also collected.
|
|
||||||
These details are compiled into a Job Summary, which is visible in the GitHub Actions UI.
|
|
||||||
|
|
||||||
Generation of a Job Summary is enabled by default for all Jobs using The `setup-gradle` action. This feature can be configured
|
|
||||||
so that a Job Summary is never generated, or so that a Job Summary is only generated on build failure:
|
|
||||||
```yaml
|
|
||||||
add-job-summary: 'on-failure' # Valid values are 'always' (default), 'never', and 'on-failure'
|
|
||||||
```
|
|
||||||
|
|
||||||
### Adding Job Summary as a Pull Request comment
|
|
||||||
|
|
||||||
It is sometimes more convenient to view the results of a GitHub Actions Job directly from the Pull Request that triggered
|
|
||||||
the Job. For this purpose you can configure the action so that Job Summary data is added as a Pull Request comment.
|
|
||||||
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: CI
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
pull-requests: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
run-gradle-build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout project sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
add-job-summary-as-pr-comment: on-failure # Valid values are 'never' (default), 'always', and 'on-failure'
|
|
||||||
- run: ./gradlew build --scan
|
|
||||||
```
|
|
||||||
|
|
||||||
Note that in order to add a Pull Request comment, the workflow must be configured with the `pull-requests: write` permission.
|
|
||||||
|
|
||||||
|
|
||||||
### Build Scan® link as Step output
|
|
||||||
|
|
||||||
As well as reporting all [Build Scan](https://gradle.com/build-scans/) links in the Job Summary,
|
|
||||||
The `setup-gradle` action action makes this link available an an output of any Step that executes Gradle.
|
|
||||||
|
|
||||||
The output name is `build-scan-url`. You can then use the build scan link in subsequent actions of your workflow.
|
|
||||||
|
|
||||||
### Saving arbitrary build outputs
|
|
||||||
|
|
||||||
By default, a GitHub Actions workflow using `setup-gradle` will record the log output and any Build Scan
|
|
||||||
links for your build, but any output files generated by the build will not be saved.
|
|
||||||
|
|
||||||
To save selected files from your build execution, you can use the core [Upload-Artifact](https://github.com/actions/upload-artifact) action.
|
|
||||||
For example:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
gradle:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout project sources
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
- name: Run build with Gradle wrapper
|
|
||||||
run: ./gradlew build --scan
|
|
||||||
- name: Upload build reports
|
|
||||||
uses: actions/upload-artifact@v3
|
|
||||||
if: always()
|
|
||||||
with:
|
|
||||||
name: build-reports
|
|
||||||
path: build/reports/
|
|
||||||
```
|
|
||||||
|
|
||||||
### Use of custom init-scripts in Gradle User Home
|
|
||||||
|
|
||||||
Note that the action collects information about Gradle invocations via an [Initialization Script](https://docs.gradle.org/current/userguide/init_scripts.html#sec:using_an_init_script)
|
|
||||||
located at `USER_HOME/.gradle/init.d/gradle-actions.build-result-capture.init.gradle`.
|
|
||||||
|
|
||||||
If you are adding any custom init scripts to the `USER_HOME/.gradle/init.d` directory, it may be necessary to ensure these files are applied prior to `gradle-actions.build-result-capture.init.gradle`.
|
|
||||||
Since Gradle applies init scripts in alphabetical order, one way to ensure this is via file naming.
|
|
||||||
|
|
||||||
## Support for GitHub Enterprise Server (GHES)
|
|
||||||
|
|
||||||
You can use The `setup-gradle` action on GitHub Enterprise Server, and benefit from the improved integration with Gradle. Depending on the version of GHES you are running, certain features may be limited:
|
|
||||||
- Build Scan links are captured and displayed in the GitHub Actions UI
|
|
||||||
- Easily run your build with different versions of Gradle
|
|
||||||
- Save/restore of Gradle User Home (requires GHES v3.5+ : GitHub Actions cache was introduced in GHES 3.5)
|
|
||||||
- Support for GitHub Actions Job Summary (requires GHES 3.6+ : GitHub Actions Job Summary support was introduced in GHES 3.6). In earlier versions of GHES the build-results summary and caching report will be written to the workflow log, as part of the post-action step.
|
|
||||||
|
|
||||||
## GitHub Dependency Graph support
|
|
||||||
|
|
||||||
> [!IMPORTANT]
|
|
||||||
> The simplest (and recommended) way to generate a dependency graph is via a separate workflow
|
|
||||||
> using `gradle/actions/dependency-submission`. This action will attempt to detect all dependencies used by your build
|
|
||||||
> without building and testing the project itself.
|
|
||||||
>
|
|
||||||
> See the [dependency-submission documentation](../dependency-submission/README.md) for up-to-date documentation.
|
|
||||||
|
|
||||||
|
|
||||||
The `setup-gradle` action has support for submitting a [GitHub Dependency Graph](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph) snapshot via the [GitHub Dependency Submission API](https://docs.github.com/en/rest/dependency-graph/dependency-submission?apiVersion=2022-11-28).
|
|
||||||
|
|
||||||
The dependency graph snapshot is generated via integration with the [GitHub Dependency Graph Gradle Plugin](https://plugins.gradle.org/plugin/org.gradle.github-dependency-graph-gradle-plugin), and saved as a workflow artifact. The generated snapshot files can be submitted either in the same job, or in a subsequent job (in the same or a dependent workflow).
|
|
||||||
|
|
||||||
The generated dependency graph snapshot reports all of the dependencies that were resolved during a build execution, and is used by GitHub to generate [Dependabot Alerts](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts) for vulnerable dependencies, as well as to populate the [Dependency Graph insights view](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/exploring-the-dependencies-of-a-repository#viewing-the-dependency-graph).
|
|
||||||
|
|
||||||
### Basic usage
|
|
||||||
|
|
||||||
You enable GitHub Dependency Graph support by setting the `dependency-graph` action parameter. Valid values are:
|
|
||||||
|
|
||||||
| Option | Behaviour |
|
|
||||||
| --- | --- |
|
|
||||||
| `disabled` | Do not generate a dependency graph for any build invocations.<p>This is the default. |
|
|
||||||
| `generate` | Generate a dependency graph snapshot for each build invocation. |
|
|
||||||
| `generate-and-submit` | Generate a dependency graph snapshot for each build invocation, and submit these via the Dependency Submission API on completion of the job. |
|
|
||||||
| `generate-and-upload` | Generate a dependency graph snapshot for each build invocation, saving as a workflow artifact. |
|
|
||||||
| `download-and-submit` | Download any previously saved dependency graph snapshots, and submit them via the Dependency Submission API. This can be useful to submit [dependency graphs for pull requests submitted from a repository forks](#dependency-graphs-for-pull-request-workflows). |
|
|
||||||
|
|
||||||
Example of a CI workflow that generates and submits a dependency graph:
|
|
||||||
```yaml
|
|
||||||
name: CI build
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- name: Checkout sources
|
||||||
- name: Setup Gradle to generate and submit dependency graphs
|
uses: actions/checkout@v4
|
||||||
uses: gradle/actions/setup-gradle@v3
|
- name: Setup Java
|
||||||
|
uses: actions/setup-java@v4
|
||||||
with:
|
with:
|
||||||
dependency-graph: generate-and-submit
|
distribution: 'temurin'
|
||||||
- name: Run the usual CI build (dependency-graph will be generated and submitted post-job)
|
java-version: 17
|
||||||
run: ./gradlew build
|
|
||||||
```
|
|
||||||
|
|
||||||
The `contents: write` permission is required in order to submit (but not generate) the dependency graph file.
|
|
||||||
Depending on [repository settings](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token), this permission may be available by default or may need to be explicitly enabled in the workflow file (as above).
|
|
||||||
|
|
||||||
> [!IMPORTANT]
|
|
||||||
> The above configuration will work for workflows that run as a result of commits to a repository branch,
|
|
||||||
> but not when a workflow is triggered by a PR from a repository fork.
|
|
||||||
> This is because the `contents: write` permission is not available when executing a workflow
|
|
||||||
> for a PR submitted from a forked repository.
|
|
||||||
> For a configuration that supports this setup, see [Dependency Graphs for pull request workflows](#dependency-graphs-for-pull-request-workflows).
|
|
||||||
|
|
||||||
### Making dependency graph failures cause Job failures
|
|
||||||
|
|
||||||
By default, if a failure is encountered when generating or submitting the dependency graph, the action will log the failure as a warning and continue.
|
|
||||||
This allows your workflow to be resilient to dependency graph failures, in case dependency graph production is a side-effect rather than the primary purpose of a workflow.
|
|
||||||
|
|
||||||
If instead you have a workflow that has a primary purpose to generate and submit a dependency graph, then it makes sense for this workflow to fail if the dependency
|
|
||||||
graph cannot be generated or submitted. You can enable this behaviour with the `dependency-graph-continue-on-failure` parameter, which defaults to `true`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# Ensure that the workflow Job will fail if the dependency graph cannot be submitted
|
|
||||||
- uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-submit
|
|
||||||
dependency-graph-continue-on-failure: false
|
|
||||||
```
|
|
||||||
|
|
||||||
### Using a custom plugin repository
|
|
||||||
|
|
||||||
By default, the action downloads the `github-dependency-graph-gradle-plugin` from the Gradle Plugin Portal (https://plugins.gradle.org). If your GitHub Actions environment does not have access to this URL, you can specify a custom plugin repository to use.
|
|
||||||
Do so by setting the `GRADLE_PLUGIN_REPOSITORY_URL` environment variable with your Gradle invocation.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle to generate and submit dependency graphs
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-submit
|
|
||||||
- name: Run a build, resolving the 'dependency-graph' plugin from the plugin portal proxy
|
|
||||||
run: ./gradlew build
|
|
||||||
env:
|
|
||||||
GRADLE_PLUGIN_REPOSITORY_URL: "https://gradle-plugins-proxy.mycorp.com"
|
|
||||||
```
|
|
||||||
|
|
||||||
### Choosing which Gradle invocations will generate a dependency graph
|
|
||||||
|
|
||||||
Once you enable the dependency graph support for a workflow job (via the `dependency-graph` parameter), dependencies will be collected and reported for all subsequent Gradle invocations.
|
|
||||||
If you have a Gradle build step that you want to exclude from dependency graph generation, you can set the `GITHUB_DEPENDENCY_GRAPH_ENABLED` environment variable to `false`.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle to generate and submit dependency graphs
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
dependency-graph: generate-and-submit
|
|
||||||
- name: Build the app, generating a graph of dependencies required
|
|
||||||
run: ./gradlew :my-app:assemble
|
|
||||||
- name: Run all checks, disabling dependency graph generation
|
|
||||||
run: ./gradlew check
|
|
||||||
env:
|
|
||||||
GITHUB_DEPENDENCY_GRAPH_ENABLED: false
|
|
||||||
```
|
|
||||||
|
|
||||||
### Filtering which Gradle Configurations contribute to the dependency graph
|
|
||||||
|
|
||||||
If you do not want the dependency graph to include every dependency configuration in every project in your build,
|
|
||||||
you can limit the dependency extraction to a subset of these.
|
|
||||||
|
|
||||||
See the documentation for [dependency-submission](../dependency-submission/README.md) and the
|
|
||||||
[GitHub Dependency Graph Gradle Plugin](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#filtering-which-gradle-configurations-contribute-to-the-dependency-graph) for details.
|
|
||||||
|
|
||||||
### Gradle version compatibility
|
|
||||||
|
|
||||||
Dependency-graph generation is compatible with most versions of Gradle >= `5.2`, and is tested regularly against
|
|
||||||
Gradle versions `5.2.1`, `5.6.4`, `6.0.1`, `6.9.4`, `7.1.1` and `7.6.3`, as well as all patched versions of Gradle 8.x.
|
|
||||||
|
|
||||||
A known exception to this is that Gradle `7.0`, `7.0.1` and `7.0.2` are not supported.
|
|
||||||
|
|
||||||
See [here](https://github.com/gradle/github-dependency-graph-gradle-plugin?tab=readme-ov-file#gradle-compatibility) for complete compatibility information.
|
|
||||||
|
|
||||||
### Reducing storage costs for saved dependency graph artifacts
|
|
||||||
|
|
||||||
When `generate` or `generate-and-submit` is used with the action, the dependency graph that is generated is stored as a workflow artifact.
|
|
||||||
By default, these artifacts are retained for a period of 30 days (or as configured for the repository).
|
|
||||||
To reduce storage costs for these artifacts, you can set the `artifact-retention-days` value to a lower number.
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
steps:
|
|
||||||
- name: Generate dependency graph, but only retain artifact for one day
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
dependency-graph: generate
|
|
||||||
artifact-retention-days: 1
|
|
||||||
```
|
|
||||||
|
|
||||||
# Develocity plugin injection
|
|
||||||
|
|
||||||
The `setup-gradle` action provides support for injecting and configuring the Develocity Gradle plugin into any Gradle build, without any modification to the project sources.
|
|
||||||
This is achieved via an init-script installed into Gradle User Home, which is enabled and parameterized via environment variables.
|
|
||||||
|
|
||||||
The same auto-injection behavior is available for the Common Custom User Data Gradle plugin, which enriches any build scans published with additional useful information.
|
|
||||||
|
|
||||||
## Enabling Develocity injection
|
|
||||||
|
|
||||||
In order to enable Develocity injection for your build, you must provide the required configuration via environment variables.
|
|
||||||
|
|
||||||
Here's a minimal example:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Run build with Develocity injection
|
|
||||||
|
|
||||||
env:
|
|
||||||
DEVELOCITY_INJECTION_ENABLED: true
|
|
||||||
DEVELOCITY_URL: https://develocity.your-server.com
|
|
||||||
DEVELOCITY_PLUGIN_VERSION: 3.16.2
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle
|
- name: Setup Gradle
|
||||||
uses: gradle/actions/setup-gradle@v3
|
uses: gradle/actions/setup-gradle@v3
|
||||||
- name: Run a Gradle build with Develocity injection enabled
|
- name: Build with Gradle
|
||||||
run: ./gradlew build
|
run: ./gradlew build
|
||||||
```
|
```
|
||||||
|
|
||||||
This configuration will automatically apply `v3.16.2` of the [Develocity Gradle plugin](https://docs.gradle.com/enterprise/gradle-plugin/), and publish build scans to https://develocity.your-server.com.
|
See the [full action documentation](../docs/setup-gradle.md) for more advanced usage scenarios.
|
||||||
|
|
||||||
This example assumes that the `develocity.your-server.com` server allows anonymous publishing of build scans.
|
|
||||||
In the likely scenario that your Develocity server requires authentication, you will also need to configure an addition environment variable
|
|
||||||
with a valid [Develocity access key](https://docs.gradle.com/enterprise/gradle-plugin/#via_environment_variable).
|
|
||||||
|
|
||||||
## Configuring Develocity injection
|
|
||||||
|
|
||||||
The `init-script` supports a number of additional configuration parameters that you may fine useful. All configuration options (required and optional) are detailed below:
|
|
||||||
|
|
||||||
| Variable | Required | Description |
|
|
||||||
|-----------------------------------| --- | --- |
|
|
||||||
| DEVELOCITY_INJECTION_ENABLED | :white_check_mark: | enables Develocity injection |
|
|
||||||
| DEVELOCITY_URL | :white_check_mark: | the URL of the Develocity server |
|
|
||||||
| DEVELOCITY_ALLOW_UNTRUSTED_SERVER | | allow communication with an untrusted server; set to _true_ if your Develocity instance is using a self-signed certificate |
|
|
||||||
| DEVELOCITY_ENFORCE_URL | | enforce the configured Develocity URL over a URL configured in the project's build; set to _true_ to enforce publication of build scans to the configured Develocity URL |
|
|
||||||
| DEVELOCITY_PLUGIN_VERSION | :white_check_mark: | the version of the [Develocity Gradle plugin](https://docs.gradle.com/enterprise/gradle-plugin/) to apply |
|
|
||||||
| DEVELOCITY_CCUD_PLUGIN_VERSION | | the version of the [Common Custom User Data Gradle plugin](https://github.com/gradle/common-custom-user-data-gradle-plugin) to apply, if any |
|
|
||||||
| GRADLE_PLUGIN_REPOSITORY_URL | | the URL of the repository to use when resolving the Develocity and CCUD plugins; the Gradle Plugin Portal is used by default |
|
|
||||||
|
|
||||||
## Publishing to scans.gradle.com
|
|
||||||
|
|
||||||
Develocity injection is designed to enable publishing of build scans to a Develocity instance,
|
|
||||||
but is also useful for publishing to the public Build Scans instance (https://scans.gradle.com).
|
|
||||||
|
|
||||||
To publish to https://scans.gradle.com, you must specify in your workflow that you accept the [Gradle Terms of Service](https://gradle.com/terms-of-service).
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
name: Run build and publish Build Scan
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- name: Setup Gradle to publish build scans
|
|
||||||
uses: gradle/actions/setup-gradle@v3
|
|
||||||
with:
|
|
||||||
build-scan-publish: true
|
|
||||||
build-scan-terms-of-service-url: "https://gradle.com/terms-of-service"
|
|
||||||
build-scan-terms-of-service-agree: "yes"
|
|
||||||
|
|
||||||
- name: Run a Gradle build - a build scan will be published automatically
|
|
||||||
run: ./gradlew build
|
|
||||||
```
|
|
||||||
|
|||||||
@@ -1,13 +1,14 @@
|
|||||||
name: 'Setup Gradle'
|
name: 'Setup Gradle'
|
||||||
description: 'Configures Gradle for GitHub actions, caching state and generating a dependency graph via Dependency Submission.'
|
description: 'Configures Gradle for GitHub actions, caching state and generating a dependency graph via Dependency Submission.'
|
||||||
|
|
||||||
# https://help.github.com/en/articles/metadata-syntax-for-github-actions
|
|
||||||
|
|
||||||
inputs:
|
inputs:
|
||||||
gradle-version:
|
gradle-version:
|
||||||
description: Gradle version to use. If specified, this Gradle version will be downloaded, added to the PATH and used for invoking Gradle.
|
description: |
|
||||||
|
Gradle version to use. If specified, this Gradle version will be downloaded, added to the PATH and used for invoking Gradle.
|
||||||
|
If not provided, it is assumed that the project uses the Gradle Wrapper.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
# Cache configuration
|
||||||
cache-disabled:
|
cache-disabled:
|
||||||
description: When 'true', all caching is disabled. No entries will be written to or read from the cache.
|
description: When 'true', all caching is disabled. No entries will be written to or read from the cache.
|
||||||
required: false
|
required: false
|
||||||
@@ -22,7 +23,7 @@ inputs:
|
|||||||
|
|
||||||
cache-write-only:
|
cache-write-only:
|
||||||
description: |
|
description: |
|
||||||
When 'true', entries will not be restored from the cache but will be saved at the end of the Job.
|
When 'true', entries will not be restored from the cache but will be saved at the end of the Job.
|
||||||
Setting this to 'true' implies cache-read-only will be 'false'.
|
Setting this to 'true' implies cache-read-only will be 'false'.
|
||||||
required: false
|
required: false
|
||||||
default: false
|
default: false
|
||||||
@@ -34,11 +35,24 @@ inputs:
|
|||||||
|
|
||||||
cache-encryption-key:
|
cache-encryption-key:
|
||||||
description: |
|
description: |
|
||||||
A base64 encoded AES key used to encrypt the configuration-cache data. The key is exported as 'GRADLE_ENCRYPTION_KEY' for later steps.
|
A base64 encoded AES key used to encrypt the configuration-cache data. The key is exported as 'GRADLE_ENCRYPTION_KEY' for later steps.
|
||||||
A suitable key can be generated with `openssl rand -base64 16`.
|
A suitable key can be generated with `openssl rand -base64 16`.
|
||||||
Configuration-cache data will not be saved/restored without an encryption key being provided.
|
Configuration-cache data will not be saved/restored without an encryption key being provided.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
cache-cleanup:
|
||||||
|
description: |
|
||||||
|
Specifies if the action should attempt to remove any stale/unused entries from the Gradle User Home prior to saving to the GitHub Actions cache.
|
||||||
|
By default, no cleanup is performed. It can be configured to run every time, or only when all Gradle builds succeed for the Job.
|
||||||
|
Valid values are 'never', 'on-success' and 'always'.
|
||||||
|
required: false
|
||||||
|
default: 'on-success'
|
||||||
|
|
||||||
|
gradle-home-cache-cleanup:
|
||||||
|
description: When 'true', the action will attempt to remove any stale/unused entries from the Gradle User Home prior to saving to the GitHub Actions cache.
|
||||||
|
required: false
|
||||||
|
deprecation-message: This input has been superceded by the 'cache-cleanup' input parameter.
|
||||||
|
|
||||||
gradle-home-cache-includes:
|
gradle-home-cache-includes:
|
||||||
description: Paths within Gradle User Home to cache.
|
description: Paths within Gradle User Home to cache.
|
||||||
required: false
|
required: false
|
||||||
@@ -49,15 +63,8 @@ inputs:
|
|||||||
gradle-home-cache-excludes:
|
gradle-home-cache-excludes:
|
||||||
description: Paths within Gradle User Home to exclude from cache.
|
description: Paths within Gradle User Home to exclude from cache.
|
||||||
required: false
|
required: false
|
||||||
# e.g. Use the following setting to prevent the local build cache from being saved/restored
|
|
||||||
# gradle-home-cache-excludes: |
|
|
||||||
# caches/build-cache-1
|
|
||||||
|
|
||||||
gradle-home-cache-cleanup:
|
|
||||||
description: When 'true', the action will attempt to remove any stale/unused entries from the Gradle User Home prior to saving to the GitHub Actions cache.
|
|
||||||
required: false
|
|
||||||
default: false
|
|
||||||
|
|
||||||
|
# Job summary configuration
|
||||||
add-job-summary:
|
add-job-summary:
|
||||||
description: Specifies when a Job Summary should be inluded in the action results. Valid values are 'never', 'always' (default), and 'on-failure'.
|
description: Specifies when a Job Summary should be inluded in the action results. Valid values are 'never', 'always' (default), and 'on-failure'.
|
||||||
required: false
|
required: false
|
||||||
@@ -68,53 +75,140 @@ inputs:
|
|||||||
required: false
|
required: false
|
||||||
default: 'never'
|
default: 'never'
|
||||||
|
|
||||||
|
# Dependency Graph configuration
|
||||||
dependency-graph:
|
dependency-graph:
|
||||||
description: Specifies if a GitHub dependency snapshot should be generated for each Gradle build, and if so, how. Valid values are 'disabled' (default), 'generate', 'generate-and-submit', 'generate-and-upload', 'download-and-submit' and 'clear'.
|
description: |
|
||||||
|
Specifies if a GitHub dependency snapshot should be generated for each Gradle build, and if so, how.
|
||||||
|
Valid values are 'disabled' (default), 'generate', 'generate-and-submit', 'generate-and-upload', and 'download-and-submit'.
|
||||||
required: false
|
required: false
|
||||||
default: 'disabled'
|
default: 'disabled'
|
||||||
|
|
||||||
|
dependency-graph-report-dir:
|
||||||
|
description: |
|
||||||
|
Specifies where the dependency graph report will be generated.
|
||||||
|
Paths can relative or absolute. Relative paths are resolved relative to the workspace directory.
|
||||||
|
required: false
|
||||||
|
default: 'dependency-graph-reports'
|
||||||
|
|
||||||
dependency-graph-continue-on-failure:
|
dependency-graph-continue-on-failure:
|
||||||
description: When 'false' a failure to generate or submit a dependency graph will fail the Step or Job. When 'true' a warning will be emitted but no failure will result.
|
description: When 'false' a failure to generate or submit a dependency graph will fail the Step or Job. When 'true' a warning will be emitted but no failure will result.
|
||||||
required: false
|
required: false
|
||||||
default: true
|
default: true
|
||||||
|
|
||||||
|
dependency-graph-exclude-projects:
|
||||||
|
description: |
|
||||||
|
Gradle projects that should be excluded from dependency graph (regular expression).
|
||||||
|
When set, any matching project will be excluded.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-include-projects:
|
||||||
|
description: |
|
||||||
|
Gradle projects that should be included in dependency graph (regular expression).
|
||||||
|
When set, only matching projects will be included.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-exclude-configurations:
|
||||||
|
description: |
|
||||||
|
Gradle configurations that should be included in dependency graph (regular expression).
|
||||||
|
When set, anymatching configurations will be excluded.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
dependency-graph-include-configurations:
|
||||||
|
description: |
|
||||||
|
Gradle configurations that should be included in dependency graph (regular expression).
|
||||||
|
When set, only matching configurations will be included.
|
||||||
|
required: false
|
||||||
|
|
||||||
artifact-retention-days:
|
artifact-retention-days:
|
||||||
description: Specifies the number of days to retain any artifacts generated by the action. If not set, the default retention settings for the repository will apply.
|
description: Specifies the number of days to retain any artifacts generated by the action. If not set, the default retention settings for the repository will apply.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
# Build Scan configuration
|
||||||
build-scan-publish:
|
build-scan-publish:
|
||||||
description: |
|
description: |
|
||||||
Set to 'true' to automatically publish build results as a Build Scan on scans.gradle.com.
|
Set to 'true' to automatically publish build results as a Build Scan on scans.gradle.com.
|
||||||
For publication to succeed without user input, you must also provide values for `build-scan-terms-of-service-url` and 'build-scan-terms-of-service-agree'.
|
For publication to succeed without user input, you must also provide values for `build-scan-terms-of-use-url` and 'build-scan-terms-of-use-agree'.
|
||||||
required: false
|
required: false
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
build-scan-terms-of-service-url:
|
build-scan-terms-of-use-url:
|
||||||
description: The URL to the Build Scan® terms of service. This input must be set to 'https://gradle.com/terms-of-service'.
|
description: The URL to the Build Scan® terms of use. This input must be set to 'https://gradle.com/terms-of-service' or 'https://gradle.com/help/legal-terms-of-use'.
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
build-scan-terms-of-service-agree:
|
build-scan-terms-of-use-agree:
|
||||||
description: Indicate that you agree to the Build Scan® terms of service. This input value must be "yes".
|
description: Indicate that you agree to the Build Scan® terms of use. This input value must be "yes".
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
|
develocity-access-key:
|
||||||
|
description: Develocity access key. Should be set to a secret containing the Develocity Access key.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-token-expiry:
|
||||||
|
description: The Develocity short-lived access tokens expiry in hours. Default is 2 hours.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-injection-enabled:
|
||||||
|
description: Enables Develocity injection.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-url:
|
||||||
|
description: The URL for the Develocity server.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-allow-untrusted-server:
|
||||||
|
description: Allow communication with an untrusted server; set to _true_ if your Develocity instance is using a self-signed.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-capture-file-fingerprints:
|
||||||
|
description: Enables capturing the paths and content hashes of each individual input file.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-enforce-url:
|
||||||
|
description: Enforce the configured Develocity URL over a URL configured in the project's build; set to _true_ to enforce publication of build scans to the configured Develocity URL.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-plugin-version:
|
||||||
|
description: The version of the Develocity Gradle plugin to apply.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
develocity-ccud-plugin-version:
|
||||||
|
description: The version of the Common Custom User Data Gradle plugin to apply, if any.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
gradle-plugin-repository-url:
|
||||||
|
description: The URL of the repository to use when resolving the Develocity and CCUD plugins; the Gradle Plugin Portal is used by default.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
gradle-plugin-repository-username:
|
||||||
|
description: The username for the repository URL to use when resolving the Develocity and CCUD.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
gradle-plugin-repository-password:
|
||||||
|
description: The password for the repository URL to use when resolving the Develocity and CCUD plugins; Consider using secrets to pass the value to this variable.
|
||||||
|
required: false
|
||||||
|
|
||||||
|
# Wrapper validation configuration
|
||||||
|
validate-wrappers:
|
||||||
|
description: |
|
||||||
|
When 'true' (the default) the action will automatically validate all wrapper jars found in the repository.
|
||||||
|
If the wrapper checksums are not valid, the action will fail.
|
||||||
|
required: false
|
||||||
|
default: true
|
||||||
|
|
||||||
|
allow-snapshot-wrappers:
|
||||||
|
description: |
|
||||||
|
When 'true', wrapper validation will include the checksums of snapshot wrapper jars.
|
||||||
|
Use this if you are running with nightly or snapshot versions of the Gradle wrapper.
|
||||||
|
required: false
|
||||||
|
default: false
|
||||||
|
|
||||||
# DEPRECATED ACTION INPUTS
|
# DEPRECATED ACTION INPUTS
|
||||||
arguments:
|
arguments:
|
||||||
description: Gradle command line arguments (supports multi-line input)
|
description: Gradle command line arguments (supports multi-line input)
|
||||||
required: false
|
required: false
|
||||||
deprecation-message: Using the action to execute Gradle directly is deprecated in favor of using the action to setup Gradle, and executing Gradle in a subsequent Step.
|
deprecation-message: This parameter has been deprecated and removed. It is only left here to allow for better reporting to assist users to migrate.
|
||||||
|
|
||||||
build-root-directory:
|
# EXPERIMENTAL ACTION INPUTS
|
||||||
description: Path to the root directory of the build. Default is the root of the GitHub workspace.
|
|
||||||
required: false
|
|
||||||
deprecation-message: Using the action to execute Gradle directly is deprecated in favor of using the action to setup Gradle, and executing Gradle in a subsequent Step.
|
|
||||||
|
|
||||||
generate-job-summary:
|
|
||||||
description: When 'false', no Job Summary will be generated for the Job.
|
|
||||||
required: false
|
|
||||||
default: true
|
|
||||||
deprecation-message: Superceded by the new 'add-job-summary' and 'add-job-summary-as-pr-comment' parameters.
|
|
||||||
|
|
||||||
# EXPERIMENTAL & INTERNAL ACTION INPUTS
|
|
||||||
# The following action properties allow fine-grained tweaking of the action caching behaviour.
|
# The following action properties allow fine-grained tweaking of the action caching behaviour.
|
||||||
# These properties are experimental and not (yet) designed for production use, and may change without notice in a subsequent release of `setup-gradle`.
|
# These properties are experimental and not (yet) designed for production use, and may change without notice in a subsequent release of `setup-gradle`.
|
||||||
# Use at your own risk!
|
# Use at your own risk!
|
||||||
@@ -122,7 +216,9 @@ inputs:
|
|||||||
description: When 'true', the action will not attempt to restore the Gradle User Home entries from other Jobs.
|
description: When 'true', the action will not attempt to restore the Gradle User Home entries from other Jobs.
|
||||||
required: false
|
required: false
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
|
# INTERNAL ACTION INPUTS
|
||||||
|
# These inputs should not be configured directly, and are only used to pass environmental information to the action
|
||||||
workflow-job-context:
|
workflow-job-context:
|
||||||
description: Used to uniquely identify the current job invocation. Defaults to the matrix values for this job; this should not be overridden by users (INTERNAL).
|
description: Used to uniquely identify the current job invocation. Defaults to the matrix values for this job; this should not be overridden by users (INTERNAL).
|
||||||
required: false
|
required: false
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
"no-unused-vars": "off",
|
"no-unused-vars": "off",
|
||||||
"no-shadow": "off",
|
"no-shadow": "off",
|
||||||
"sort-imports": "off",
|
"sort-imports": "off",
|
||||||
|
"github/array-foreach": "off",
|
||||||
"@typescript-eslint/no-unused-vars": ["error", { "argsIgnorePattern": "^_" }],
|
"@typescript-eslint/no-unused-vars": ["error", { "argsIgnorePattern": "^_" }],
|
||||||
"@typescript-eslint/explicit-member-accessibility": ["error", {"accessibility": "no-public"}],
|
"@typescript-eslint/explicit-member-accessibility": ["error", {"accessibility": "no-public"}],
|
||||||
"@typescript-eslint/no-require-imports": "error",
|
"@typescript-eslint/no-require-imports": "error",
|
||||||
|
|||||||
2
sources/.gitignore
vendored
2
sources/.gitignore
vendored
@@ -102,3 +102,5 @@ __tests__/runner/*
|
|||||||
.idea/
|
.idea/
|
||||||
*.iml
|
*.iml
|
||||||
|
|
||||||
|
# Local 'dist' directory within 'sources'. This is copied to ../dist by CI.
|
||||||
|
dist/
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
# Configuration file for asdf version manager
|
# Configuration file for asdf version manager
|
||||||
nodejs 20.10.0
|
nodejs 20.10.0
|
||||||
gradle 8.5
|
gradle 8.9
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
cd sources
|
|
||||||
npm run build
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
cd sources
|
|
||||||
npm run all
|
|
||||||
1958
sources/package-lock.json
generated
1958
sources/package-lock.json
generated
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user