Skip to content

[Snyk] Security upgrade python from 3.8-slim to 3.13.0rc2-slim #94

[Snyk] Security upgrade python from 3.8-slim to 3.13.0rc2-slim

[Snyk] Security upgrade python from 3.8-slim to 3.13.0rc2-slim #94

name: Build Linux Packages
on:
push:
branches:
- master
tags:
- v*.*.*
pull_request:
branches:
- master
workflow_dispatch:
schedule:
- cron: '0 4 * * *'
permissions:
contents: read
jobs:
pre_job:
name: Skip Duplicate Jobs Pre Job
runs-on: ubuntu-22.04
permissions:
actions: write # Needed for skip-duplicate-jobs job
contents: read
outputs:
should_skip: ${{ steps.skip_check.outputs.should_skip }}
python_version: ${{ steps.define_constants.outputs.python_version }}
cache_version: ${{ steps.define_constants.outputs.cache_version }}
aws_region: ${{ steps.define_constants.outputs.aws_region }}
aws_private_key_name: ${{ steps.define_constants.outputs.aws_private_key_name }}
cicd_workflow: ${{ steps.define_constants.outputs.cicd_workflow }}
steps:
- id: skip_check
uses: fkirc/skip-duplicate-actions@12aca0a884f6137d619d6a8a09fcc3406ced5281 # v4.0.0
with:
cancel_others: 'true'
github_token: ${{ github.token }}
- name: Checkout repository
uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4
- id: define_constants
run: |
echo "python_version=3.8" >> "${GITHUB_OUTPUT}"
echo "cache_version=$GITHUB_REF_NAME" >> "${GITHUB_OUTPUT}"
echo "aws_region=us-east-1" >> "${GITHUB_OUTPUT}"
echo "cicd_workflow=${{ github.run_id }}-${{ github.run_number }}-${{ github.run_attempt }}" >> "${GITHUB_OUTPUT}"
build_linux_packages:
name: "Build Linux packages"
needs:
- pre_job
uses: ./.github/workflows/reusable-agent-build-linux-packages-new.yml
with:
python_version: ${{ needs.pre_job.outputs.python_version }}
cache_version: ${{ needs.pre_job.outputs.cache_version }}
aws_region: ${{ needs.pre_job.outputs.aws_region }}
cicd_workflow: ${{ needs.pre_job.outputs.cicd_workflow }}
secrets:
CT_AWS_DEV_EC2_PRIVATE_KEY: ${{ secrets.CT_AWS_DEV_EC2_PRIVATE_KEY }}
CT_AWS_DEV_EC2_PRIVATE_KEY_NAME: ${{ secrets.CT_AWS_DEV_EC2_PRIVATE_KEY_NAME }}
CT_AWS_DEV_EC2_ACCESS_KEY: ${{ secrets.CT_AWS_DEV_EC2_ACCESS_KEY }}
CT_AWS_DEV_EC2_SECRET_KEY: ${{ secrets.CT_AWS_DEV_EC2_SECRET_KEY }}
CT_SCALYR_TOKEN_PROD_US_CLOUDTECH_TESTING_WRITE: ${{ secrets.CT_SCALYR_TOKEN_PROD_US_CLOUDTECH_TESTING_WRITE }}
CT_SCALYR_TOKEN_PROD_US_CLOUDTECH_TESTING_READ: ${{ secrets.CT_SCALYR_TOKEN_PROD_US_CLOUDTECH_TESTING_READ }}
clean-ec2-tests-objects:
name: Remove ec2 object that were created by this workflow
if: ${{ always() }}
needs:
- pre_job
- build_linux_packages
runs-on: ubuntu-20.04
steps:
- name: Checkout repository
uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608 # v4
- name: install python and requirements
uses: ./.github/actions/install_python_and_requirements
with:
python_version: ${{ needs.pre_job.outputs.python_version }}
- name: Cleanup old prefix lists for ec2 test security group.
env:
AWS_ACCESS_KEY: ${{ secrets.CT_AWS_DEV_EC2_ACCESS_KEY }}
AWS_SECRET_KEY: ${{ secrets.CT_AWS_DEV_EC2_SECRET_KEY }}
AWS_PRIVATE_KEY_NAME: ${{ secrets.CT_AWS_DEV_EC2_PRIVATE_KEY_NAME }}
AWS_PRIVATE_KEY: ${{ secrets.CT_AWS_DEV_EC2_PRIVATE_KEY }}
AWS_REGION: ${{ needs.pre_job.outputs.aws_region }}
CICD_WORKFLOW: ${{ needs.pre_job.outputs.cicd_workflow }}
run: |
python3 agent_build_refactored/utils/scripts/cicd/cleanup_ec2_objects.py