Skip to content
Snippets Groups Projects

[fix] Run CI Template Jobs on PRs

Merged Ursa (9R) requested to merge ursa/ci into develop
1 file
+ 12
5
Compare changes
  • Side-by-side
  • Inline
+ 12
5
image: registry.gitlab.com/thorchain/thornode:builder-v2@sha256:eda7a8670a92b3178b2f947f692794c19e307073cdef4ad2a28ccf8dba2a7054
image: registry.gitlab.com/thorchain/thornode:builder-v2@sha256:eda7a8670a92b3178b2f947f692794c19e307073cdef4ad2a28ccf8dba2a7054
workflow:
workflow:
rules:
rules: &rules
- if: $CI_MERGE_REQUEST_IID
- if: $CI_MERGE_REQUEST_IID
- if: $CI_COMMIT_TAG
- if: $CI_COMMIT_TAG
- if: $CI_COMMIT_REF_PROTECTED == "true"
- if: $CI_COMMIT_REF_PROTECTED == "true"
@@ -173,18 +173,25 @@ smoke-test:
@@ -173,18 +173,25 @@ smoke-test:
after_script:
after_script:
- ./scripts/docker_logs.sh
- ./scripts/docker_logs.sh
 
include:
 
- template: Security/SAST.gitlab-ci.yml
 
- template: Security/Secret-Detection.gitlab-ci.yml
 
 
# NOTE: The following included jobs have internal rule definitions that need to be
 
# overwritten for them to trigger on merge requests. We overwrite all with the default
 
# workflow rule set.
 
gosec-sast:
gosec-sast:
stage: test
stage: test
 
rules: *rules
secret_detection:
secret_detection:
stage: test
stage: test
rules: *rules
include:
- template: Security/SAST.gitlab-ci.yml
- template: Security/Secret-Detection.gitlab-ci.yml
semgrep:
semgrep:
stage: test
stage: test
 
rules: *rules
image: returntocorp/semgrep-agent:v1
image: returntocorp/semgrep-agent:v1
script: semgrep-agent --gitlab-json > gl-sast-report.json || true
script: semgrep-agent --gitlab-json > gl-sast-report.json || true
variables:
variables:
Loading