2022-02-01 02:25:54 +03:00
BIN = docker-sbom
2022-03-17 21:53:48 +03:00
REPO = sbom-cli-plugin
2022-02-01 02:25:54 +03:00
TEMP_DIR = ./.tmp
DIST_DIR = ./dist
2022-03-07 23:59:07 +03:00
SNAPSHOT_DIR = ./snapshot
RESULTS_DIR = test/results
COVER_REPORT = $( RESULTS_DIR) /unit-coverage-details.txt
COVER_TOTAL = $( RESULTS_DIR) /unit-coverage-summary.txt
2022-02-01 02:25:54 +03:00
LINT_CMD = $( TEMP_DIR) /golangci-lint run --tests= false --timeout= 2m --config .golangci.yaml
2022-03-07 23:59:07 +03:00
GOIMPORTS_CMD = $( TEMP_DIR) /gosimports -local github.com/anchore
2022-02-01 02:25:54 +03:00
RELEASE_CMD = $( TEMP_DIR) /goreleaser release --rm-dist
SNAPSHOT_CMD = $( RELEASE_CMD) --skip-publish --rm-dist --snapshot
2022-03-07 23:59:07 +03:00
OS = $( shell uname | tr '[:upper:]' '[:lower:]' )
SNAPSHOT_BIN = $( shell realpath $( shell pwd ) /$( SNAPSHOT_DIR) /$( REPO) _$( OS) _amd64/$( BIN) )
2022-02-01 02:25:54 +03:00
BOLD := $( shell tput -T linux bold)
PURPLE := $( shell tput -T linux setaf 5)
GREEN := $( shell tput -T linux setaf 2)
CYAN := $( shell tput -T linux setaf 6)
RED := $( shell tput -T linux setaf 1)
RESET := $( shell tput -T linux sgr0)
TITLE := $( BOLD) $( PURPLE)
SUCCESS := $( BOLD) $( GREEN)
2022-03-07 23:59:07 +03:00
## change these values manually if you'd like to bust the cache in CI for select test fixtures
CLI_CACHE_BUSTER = d12f51e6c910590b485b
2022-02-01 02:25:54 +03:00
## Variable assertions
2022-03-07 23:59:07 +03:00
i f n d e f R E S U L T S _ D I R
$( error RESULTS_DIR is not set )
e n d i f
2022-02-01 02:25:54 +03:00
i f n d e f T E M P _ D I R
$( error TEMP_DIR is not set )
e n d i f
i f n d e f S N A P S H O T _ D I R
$( error SNAPSHOT_DIR is not set )
e n d i f
d e f i n e t i t l e
@printf '$(TITLE)$(1)$(RESET)\n'
e n d e f
2022-03-07 23:59:07 +03:00
d e f i n e s a f e _ r m _ r f
bash -c 'test -z "$(1)" && false || rm -rf $(1)'
e n d e f
d e f i n e s a f e _ r m _ r f _ c h i l d r e n
bash -c 'test -z "$(1)" && false || rm -rf $(1)/*'
e n d e f
2022-02-01 02:25:54 +03:00
## Tasks
.PHONY : all
2022-03-07 23:59:07 +03:00
all : clean -snapshot static -analysis $( SNAPSHOT_DIR ) test ## Run all linux-based checks (linting, license check, unit, integration, and linux acceptance tests)
2022-02-01 02:25:54 +03:00
@printf '$(SUCCESS)All checks pass!$(RESET)\n'
.PHONY : test
2022-03-07 23:59:07 +03:00
test : unit install -test cli ## Run all tests
2022-02-01 02:25:54 +03:00
2022-03-07 23:59:07 +03:00
$(RESULTS_DIR) :
mkdir -p $( RESULTS_DIR)
2022-02-01 02:25:54 +03:00
2022-03-07 23:59:07 +03:00
.PHONY : bootstrap -tools
bootstrap-tools :
2022-02-01 02:25:54 +03:00
$( call title,Bootstrapping tools)
mkdir -p $( TEMP_DIR)
2022-03-22 23:57:06 +03:00
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $( TEMP_DIR) / v1.45.0
2022-02-01 02:25:54 +03:00
curl -sSfL https://raw.githubusercontent.com/wagoodman/go-bouncer/master/bouncer.sh | sh -s -- -b $( TEMP_DIR) / v0.3.0
2022-03-30 17:28:55 +03:00
curl -sSfL https://raw.githubusercontent.com/anchore/chronicle/main/install.sh | sh -s -- -b $( TEMP_DIR) / v0.4.1
2022-03-07 23:59:07 +03:00
.github/scripts/goreleaser-install.sh -b $( TEMP_DIR) / v1.5.0
# the only difference between goimports and gosimports is that gosimports removes extra whitespace between import blocks (see https://github.com/golang/go/issues/20818)
GOBIN = " $( shell realpath $( TEMP_DIR) ) " go install github.com/rinchsan/gosimports/cmd/gosimports@v0.1.5
2022-02-01 02:25:54 +03:00
.PHONY : bootstrap -go
bootstrap-go :
go mod download
.PHONY : bootstrap
2022-03-07 23:59:07 +03:00
bootstrap : $( RESULTS_DIR ) bootstrap -go bootstrap -tools ## Download and install all go dependencies (+ prep tooling in the ./tmp dir)
$( call title,Bootstrapping go dependencies)
2022-02-01 02:25:54 +03:00
.PHONY : static -analysis
static-analysis : lint check -go -mod -tidy check -licenses
.PHONY : lint
lint : ## Run gofmt + golangci lint checks
$( call title,Running linters)
# ensure there are no go fmt differences
@printf " files with gofmt issues: [ $( shell gofmt -l -s .) ]\n "
@test -z " $( shell gofmt -l -s .) "
# run all golangci-lint rules
$( LINT_CMD)
2022-03-07 23:59:07 +03:00
@[ -z " $( shell $( GOIMPORTS_CMD) -d .) " ] && echo "goimports clean" || ( echo "goimports needs to be fixed" && false )
2022-02-01 02:25:54 +03:00
# go tooling does not play well with certain filename characters, ensure the common cases don't result in future "go get" failures
$( eval MALFORMED_FILENAMES := $( shell find . | grep -e ':' ) )
@bash -c " [[ ' $( MALFORMED_FILENAMES) ' == '' ]] || (printf '\nfound unsupported filename characters:\n $( MALFORMED_FILENAMES) \n\n' && false) "
.PHONY : lint -fix
lint-fix : ## Auto-format all source code + run golangci lint fixers
$( call title,Running lint fixers)
gofmt -w -s .
2022-03-07 23:59:07 +03:00
$( GOIMPORTS_CMD) -w .
2022-02-01 02:25:54 +03:00
$( LINT_CMD) --fix
go mod tidy
.PHONY : check -licenses
check-licenses : ## Ensure transitive dependencies are compliant with the current license policy
$( TEMP_DIR) /bouncer check
check-go-mod-tidy :
@ .github/scripts/go-mod-tidy-check.sh && echo "go.mod and go.sum are tidy!"
.PHONY : unit
2022-03-08 22:43:17 +03:00
unit : $( RESULTS_DIR ) ## Run unit tests
2022-02-01 02:25:54 +03:00
$( call title,Running unit tests)
2022-03-17 21:53:48 +03:00
go test -coverprofile $( COVER_REPORT) $( shell go list ./... | grep -v docker/sbom-cli-plugin/test)
2022-03-07 23:59:07 +03:00
@go tool cover -func $( COVER_REPORT) | grep total | awk '{print substr($$3, 1, length($$3)-1)}' > $( COVER_TOTAL)
@echo " Coverage: $$ (cat $( COVER_TOTAL) ) "
2022-02-01 02:25:54 +03:00
2022-02-01 17:03:31 +03:00
# note: this is used by CI to determine if the install test fixture cache (docker image tars) should be busted
install-fingerprint :
cd test/install && \
make cache.fingerprint
2022-02-01 21:01:13 +03:00
install-test :
2022-02-01 17:03:31 +03:00
cd test/install && \
make
2022-02-01 21:01:13 +03:00
install-test-cache-save :
2022-02-01 17:03:31 +03:00
cd test/install && \
make save
2022-02-01 21:01:13 +03:00
install-test-cache-load :
2022-02-01 17:03:31 +03:00
cd test/install && \
make load
2022-02-01 21:01:13 +03:00
install-test-ci-mac :
2022-02-01 17:03:31 +03:00
cd test/install && \
make ci-test-mac
2022-03-07 23:59:07 +03:00
# note: this is used by CI to determine if the integration test fixture cache (docker image tars) should be busted
cli-fingerprint :
$( call title,CLI test fixture fingerprint)
find test/cli/test-fixtures/image-* -type f -exec md5sum { } + | awk '{print $1}' | sort | md5sum | tee test/cli/test-fixtures/cache.fingerprint && echo " $( CLI_CACHE_BUSTER) " >> test/cli/test-fixtures/cache.fingerprint
.PHONY : cli
cli : $( SNAPSHOT_DIR ) ## Run CLI tests
chmod 755 " $( SNAPSHOT_BIN) "
SYFT_BINARY_LOCATION = '$(SNAPSHOT_BIN)' \
go test -count= 1 -v ./test/cli
2022-02-01 02:25:54 +03:00
$(SNAPSHOT_DIR) : $( TEMP_DIR ) ## Build snapshot release binaries and packages
$( call title,Building snapshot artifacts)
# create a config with the dist dir overridden
echo " dist: $( SNAPSHOT_DIR) " > $( TEMP_DIR) /goreleaser.yaml
cat .goreleaser.yaml >> $( TEMP_DIR) /goreleaser.yaml
$( SNAPSHOT_CMD) --config $( TEMP_DIR) /goreleaser.yaml
2022-03-07 23:59:07 +03:00
.PHONY : install -snapshot
install-snapshot :
cp $( SNAPSHOT_BIN) ~/.docker/cli-plugins/
.PHONY : changelog
changelog : clean -changelog CHANGELOG .md
@docker run -it --rm \
-v $( shell pwd ) /CHANGELOG.md:/CHANGELOG.md \
rawkode/mdv \
-t 748.5989 \
/CHANGELOG.md
CHANGELOG.md :
$( TEMP_DIR) /chronicle -vv > CHANGELOG.md
.PHONY : validate -syft -release -version
validate-syft-release-version :
@./.github/scripts/syft-released-version-check.sh
2022-02-01 02:25:54 +03:00
.PHONY : release
2022-03-07 23:59:07 +03:00
release : clean -dist CHANGELOG .md
2022-02-01 02:25:54 +03:00
$( call title,Publishing release artifacts)
2022-03-08 00:08:32 +03:00
bash -c " $( RELEASE_CMD) --release-notes <(cat CHANGELOG.md) "
2022-02-01 02:25:54 +03:00
.PHONY : clean
2022-03-07 23:59:07 +03:00
clean : clean -dist clean -snapshot ## Remove previous builds, result reports, and test cache
$( call safe_rm_rf_children,$( RESULTS_DIR) )
2022-02-01 02:25:54 +03:00
.PHONY : clean -snapshot
clean-snapshot :
2022-03-07 23:59:07 +03:00
$( call safe_rm_rf,$( SNAPSHOT_DIR) )
rm -f $( TEMP_DIR) /goreleaser.yaml
2022-02-01 02:25:54 +03:00
.PHONY : clean -dist
clean-dist : clean -changelog
2022-03-07 23:59:07 +03:00
$( call safe_rm_rf,$( DIST_DIR) )
rm -f $( TEMP_DIR) /goreleaser.yaml
2022-02-01 02:25:54 +03:00
.PHONY : clean -changelog
clean-changelog :
rm -f CHANGELOG.md
2022-03-07 23:59:07 +03:00
2022-02-01 02:25:54 +03:00
.PHONY : clean -tmp
clean-tmp :
rm -rf $( TEMP_DIR)
.PHONY : help
help :
@grep -E '^[a-zA-Z_-]+:.*?## .*$$' $( MAKEFILE_LIST) | sort | awk 'BEGIN {FS = ":.*?## "}; {printf "$(BOLD)$(CYAN)%-25s$(RESET)%s\n", $$1, $$2}'