debian-koji-osbuild/.github/workflows/coverity_scan.yml
dependabot[bot] 1389c20247 build(deps): bump actions/checkout from 2 to 3
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v2...v3)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-03-24 00:24:57 +01:00

38 lines
1.5 KiB
YAML

name: Coverity Scan
on:
# https://docs.github.com/en/actions/learn-github-actions/events-that-trigger-workflows#scheduled-events
schedule:
- cron: '0 4 * * *' # Daily at 04:00 UTC
jobs:
coverity_scan:
runs-on: ubuntu-latest
steps:
- name: Clone repository
uses: actions/checkout@v3
# https://scan.coverity.com/projects/osbuild-osbuild-composer
- name: Run coverity scan script
env:
COVERITY_SCAN_PROJECT_NAME: "osbuild/koji-osbuild"
COVERITY_SCAN_TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
COVERITY_SCAN_EMAIL: ${{ secrets.COVERITY_SCAN_EMAIL }}
run: |
echo "Downloading coverity scan package."
curl -o /tmp/cov-analysis-linux64.tgz https://scan.coverity.com/download/linux64 \
--form project="$COVERITY_SCAN_PROJECT_NAME" \
--form token="$COVERITY_SCAN_TOKEN"
pushd /tmp && tar xzvf cov-analysis-linux64.tgz && popd
mkdir bin
/tmp/cov-analysis-linux64-*/bin/cov-build --dir cov-int --no-command --fs-capture-search .
tar czvf cov-int.tar.gz cov-int
echo "Uploading coverity scan result to http://scan.coverity.com"
curl https://scan.coverity.com/builds?project="$COVERITY_SCAN_PROJECT_NAME" \
--form token="$COVERITY_SCAN_TOKEN" \
--form email="$COVERITY_SCAN_EMAIL" \
--form file=@cov-int.tar.gz \
--form version="$(git rev-parse HEAD)" \
--form description="$GITHUB_REF / $GITHUB_SHA"