diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml new file mode 100644 index 0000000..f583af4 --- /dev/null +++ b/.github/workflows/codeql.yaml @@ -0,0 +1,40 @@ +name: "CodeQL" + +on: + push: + branches: [ "master" ] + pull_request: + branches: [ "master" ] + +jobs: + analyze: + name: Analyze + runs-on: ubuntu-latest + permissions: + security-events: write + packages: read + actions: read + contents: read + + strategy: + fail-fast: false + matrix: + include: + - language: actions + build-mode: none + - language: csharp + build-mode: none + + steps: + - uses: actions/checkout@v5 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix.build-mode }} + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 + with: + category: "/language:${{matrix.language}}" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 1d6389b..14c5cf5 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -1,4 +1,3 @@ -# This runs when a tag gets pushed matching the format below name: Release on: @@ -12,7 +11,11 @@ env: jobs: build: - runs-on: ubuntu-latest + permissions: + contents: read + packages: write + + runs-on: windows-latest steps: - uses: actions/checkout@v5 @@ -23,6 +26,7 @@ jobs: uses: actions/setup-dotnet@v5 with: dotnet-version: 8.0.x + cache-dependency-path: '**/packages.lock.json' - name: Restore run: dotnet restore @@ -31,16 +35,16 @@ jobs: run: dotnet build --configuration Release --no-restore - name: Test - run: dotnet test --configuration Release --no-build --verbosity normal + run: dotnet test --configuration Release --no-build --no-restore --verbosity normal - name: Pack - run: dotnet pack --configuration Release -p:PackageVersion=${{ github.ref_name }} --output artifacts/ + run: dotnet pack --no-build --no-restore --configuration Release -p:PackageVersion=${{ github.ref_name }} --output artifacts/ - name: Publish to GitHub working-directory: artifacts run: | dotnet nuget add source --username ${{ github.actor }} --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/scientistproject/index.json" - dotnet nuget push --source github *.nupkg + dotnet nuget push *.nupkg --api-key ${{ secrets.GITHUB_TOKEN }} --source github - name: Publish to NuGet working-directory: artifacts diff --git a/.github/workflows/unit-test.yaml b/.github/workflows/unit-test.yaml new file mode 100644 index 0000000..ca7ea20 --- /dev/null +++ b/.github/workflows/unit-test.yaml @@ -0,0 +1,47 @@ +name: Unit test + +on: + pull_request: + branches: ["master"] + +env: + DOTNET_CLI_TELEMETRY_OPTOUT: true + DOTNET_NOLOGO: true + DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true + +jobs: + test: + permissions: + contents: read + + strategy: + fail-fast: false + matrix: + include: + - framework: net8.0 + sdk: 8.0.x + os: ubuntu-latest + - framework: net48 + sdk: none + os: windows-latest + + runs-on: ${{ matrix.os }} + + steps: + - uses: actions/checkout@v5 + + - name: Setup .NET (skip for net48) + if: matrix.sdk != 'none' + uses: actions/setup-dotnet@v5 + with: + dotnet-version: ${{ matrix.sdk }} + cache-dependency-path: '**/packages.lock.json' + + - name: Restore + run: dotnet restore + + - name: Build + run: dotnet build --configuration Release --no-restore + + - name: Test + run: dotnet test --no-build --no-restore --framework ${{ matrix.framework }} --configuration Release --verbosity normal \ No newline at end of file diff --git a/NuGet.config b/NuGet.config index 2805dff..6ce9759 100644 --- a/NuGet.config +++ b/NuGet.config @@ -1,4 +1,4 @@ - +