From 378f984afed9b671168144948457513ad2a1bcef Mon Sep 17 00:00:00 2001 From: Patrik Korytar Date: Wed, 26 Aug 2026 14:22:19 +0200 Subject: [PATCH] Add shared GH workflows --- .github/workflows/maven-build.yml | 67 ------------------------ .github/workflows/maven-mend-pr.yml | 34 ++++++++++++ .github/workflows/maven-mend.yml | 37 +++++++++++++ .github/workflows/maven-pr.yml | 16 ++++++ .github/workflows/maven-release.yml | 23 ++++++++ .github/workflows/maven-set-version.yml | 24 +++++++++ .github/workflows/maven-snapshot.yml | 18 +++++++ .github/workflows/validate-gh-action.yml | 11 ++++ 8 files changed, 163 insertions(+), 67 deletions(-) delete mode 100644 .github/workflows/maven-build.yml create mode 100644 .github/workflows/maven-mend-pr.yml create mode 100644 .github/workflows/maven-mend.yml create mode 100644 .github/workflows/maven-pr.yml create mode 100644 .github/workflows/maven-release.yml create mode 100644 .github/workflows/maven-set-version.yml create mode 100644 .github/workflows/maven-snapshot.yml create mode 100644 .github/workflows/validate-gh-action.yml diff --git a/.github/workflows/maven-build.yml b/.github/workflows/maven-build.yml deleted file mode 100644 index 0695f6e3..00000000 --- a/.github/workflows/maven-build.yml +++ /dev/null @@ -1,67 +0,0 @@ -# -# Copyright (C) 2012-2022 Red Hat, Inc. (nos-devel@redhat.com) -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -name: build on maven - -on: - watch: - types: [started] - pull_request: - types: [opened, reopened, edited, synchronize, ready_for_review] - push: - branches: - - main - - master - - workflow_dispatch: - -jobs: - build: - name: Build with maven - runs-on: ubuntu-latest - env: - MAVEN_OPTS: "-Xmx4096m -Xms2048m -XX:MaxMetaspaceSize=4096m -Xss8m" - steps: - - uses: actions/checkout@v7 - - - name: Set up JDK 11 for x64 - uses: actions/setup-java@v5.7.0 - with: - java-version: '11' - distribution: 'temurin' - architecture: x64 - - - uses: s4u/maven-settings-action@v4.0.0 - with: - sonatypeSnapshots: true - - - name: Build the Maven verify phase - run: mvn -B -V clean verify -Prun-its -Pci - - - - uses: s4u/maven-settings-action@v4.0.0 - if: ${{ github.event_name == 'push' }} - with: - servers: | - [{ - "id": "central-portal-snapshots", - "username": "${{ secrets.SONATYPE_BOT_USERNAME }}", - "password": "${{ secrets.SONATYPE_BOT_TOKEN }}" - }] - - - name: Deploy the artifact - if: ${{ github.event_name == 'push' }} - run: mvn help:effective-settings -B -V clean deploy -e diff --git a/.github/workflows/maven-mend-pr.yml b/.github/workflows/maven-mend-pr.yml new file mode 100644 index 00000000..45afc22b --- /dev/null +++ b/.github/workflows/maven-mend-pr.yml @@ -0,0 +1,34 @@ +name: Mend CLI scan for Maven PR + +on: + workflow_run: # zizmor: ignore[dangerous-triggers] + workflows: ["Java CI with Maven"] + types: [completed] + +permissions: + contents: read + actions: read + checks: write + pull-requests: write + security-events: write + +concurrency: + group: mend-scan-${{ github.event.workflow_run.pull_requests[0].number || github.event.workflow_run.head_sha }} + cancel-in-progress: true + +jobs: + scan: + if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'pull_request' + uses: project-ncl/shared-github-actions/.github/workflows/mend-ci.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + project_name: "Commonjava/atlas" + SCA: true + SAST: true + triggering_run_id: ${{ github.event.workflow_run.id }} + pr_feedback: true + secrets: + MEND_URL: ${{ secrets.MEND_URL }} + MEND_USER_KEY: ${{ secrets.MEND_USER_KEY }} + MEND_EMAIL: ${{ secrets.MEND_EMAIL }} + MEND_ORGNAME: ${{ secrets.MEND_ORGNAME }} + MEND_PRODUCTNAME: ${{ secrets.MEND_PRODUCTNAME }} diff --git a/.github/workflows/maven-mend.yml b/.github/workflows/maven-mend.yml new file mode 100644 index 00000000..a1412169 --- /dev/null +++ b/.github/workflows/maven-mend.yml @@ -0,0 +1,37 @@ +name: Mend CLI scan for Maven + +on: + push: + branches: + - master + schedule: + - cron: "0 22 * * 0" + +permissions: + contents: read + actions: read + checks: write + pull-requests: write + security-events: write + +jobs: + build: + uses: project-ncl/shared-github-actions/.github/workflows/maven-ci.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + java_version: "11" + build_command: "MAVEN_OPTS='-Xmx4096m -Xms2048m -XX:MaxMetaspaceSize=4096m -Xss8m' mvn -B -V clean verify -Prun-its -Pci" + upload_artifacts: true + + call-mend-ci: + needs: build + uses: project-ncl/shared-github-actions/.github/workflows/mend-ci.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + project_name: "Commonjava/atlas" + SCA: true + SAST: true + secrets: + MEND_URL: ${{ secrets.MEND_URL }} + MEND_USER_KEY: ${{ secrets.MEND_USER_KEY }} + MEND_EMAIL: ${{ secrets.MEND_EMAIL }} + MEND_ORGNAME: ${{ secrets.MEND_ORGNAME }} + MEND_PRODUCTNAME: ${{ secrets.MEND_PRODUCTNAME }} diff --git a/.github/workflows/maven-pr.yml b/.github/workflows/maven-pr.yml new file mode 100644 index 00000000..3d4cecd7 --- /dev/null +++ b/.github/workflows/maven-pr.yml @@ -0,0 +1,16 @@ +name: Java CI with Maven + +permissions: + contents: read + +on: + pull_request: + branches: ["*"] + +jobs: + call-maven-ci: + uses: project-ncl/shared-github-actions/.github/workflows/maven-ci.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + java_version: "11" + build_command: "MAVEN_OPTS='-Xmx4096m -Xms2048m -XX:MaxMetaspaceSize=4096m -Xss8m' mvn -B -V clean verify -Prun-its -Pci" + upload_artifacts: true diff --git a/.github/workflows/maven-release.yml b/.github/workflows/maven-release.yml new file mode 100644 index 00000000..d1ee5435 --- /dev/null +++ b/.github/workflows/maven-release.yml @@ -0,0 +1,23 @@ +name: "0 Central Release Job" # Adding the 0 so that it's on top of the list of github actions +on: + workflow_dispatch: # Manual trigger so you don't release on every push + inputs: + ref_to_release: + description: "[Optional] Branch or commit to release. Default: Github default branch" + required: false + type: string + # default has to be a static string, no variables allowed + default: "" + +jobs: + call-release-job: + permissions: + contents: write # needed to push commit and tag back to the repository + uses: project-ncl/shared-github-actions/.github/workflows/maven-release.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + ref_to_release: ${{ inputs.ref_to_release }} + secrets: + SONATYPE_USERNAME: ${{ secrets.SONATYPE_USERNAME }} + SONATYPE_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} + GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} diff --git a/.github/workflows/maven-set-version.yml b/.github/workflows/maven-set-version.yml new file mode 100644 index 00000000..36c84462 --- /dev/null +++ b/.github/workflows/maven-set-version.yml @@ -0,0 +1,24 @@ +name: "0 Maven Set Version Job" # Adding the 0 so that it's on top of the list of github actions +on: + workflow_dispatch: # Manual trigger + inputs: + new_version: + description: "[Required] Version to set" + required: true + type: string + + ref_for_version: + description: "[Optional] Branch or commit to change version. Default: Github default branch" + required: false + type: string + # default has to be a static string, no variables allowed + default: "" + +jobs: + call-maven-set-version-job: + permissions: + contents: write # needed to push commit and tag back to the repository + uses: project-ncl/shared-github-actions/.github/workflows/maven-set-version.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + new_version: ${{ inputs.new_version }} + ref_for_version: ${{ inputs.ref_for_version }} diff --git a/.github/workflows/maven-snapshot.yml b/.github/workflows/maven-snapshot.yml new file mode 100644 index 00000000..c46dbf37 --- /dev/null +++ b/.github/workflows/maven-snapshot.yml @@ -0,0 +1,18 @@ +name: Build snapshot version and upload to Maven Central + +on: + push: + branches: ["master"] + +permissions: {} + +jobs: + call-snapshot-job: + uses: project-ncl/shared-github-actions/.github/workflows/maven-snapshot.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23 + with: + project_name: "Commonjava/atlas" + snapshot_deploy_command: "mvn help:effective-settings -B -V clean deploy -e" + jboss_parent_override: "-DaltSnapshotDeploymentRepository=central-publisher::https://central.sonatype.com/repository/maven-snapshots/" + secrets: + SONATYPE_USERNAME: ${{ secrets.SONATYPE_BOT_USERNAME }} + SONATYPE_PASSWORD: ${{ secrets.SONATYPE_BOT_TOKEN }} diff --git a/.github/workflows/validate-gh-action.yml b/.github/workflows/validate-gh-action.yml new file mode 100644 index 00000000..99413792 --- /dev/null +++ b/.github/workflows/validate-gh-action.yml @@ -0,0 +1,11 @@ +name: Validate GitHub Actions Workflows +permissions: {} + +on: + pull_request: + paths: + - ".github/workflows/*.yml" + +jobs: + validate: + uses: project-ncl/shared-github-actions/.github/workflows/validate-gh-action.yml@646d9b629925d6405fb06ed1476aefd6b2cdca86 # v0.0.23