From 3a3ac3e13a442023907cfeb8e0e5addacd5c2977 Mon Sep 17 00:00:00 2001 From: Mitch Zhu Date: Fri, 21 Feb 2025 01:08:04 +0000 Subject: [PATCH] Remove debug check --- .github/workflows/binskim.yaml | 21 +++++++++------------ .github/workflows/clippy.yaml | 5 +---- .github/workflows/nancy.yaml | 5 +---- 3 files changed, 11 insertions(+), 20 deletions(-) diff --git a/.github/workflows/binskim.yaml b/.github/workflows/binskim.yaml index 1c6c4ca69224..062032049871 100644 --- a/.github/workflows/binskim.yaml +++ b/.github/workflows/binskim.yaml @@ -3,10 +3,7 @@ name: BinSkim Security Scan on: pull_request: branches: - - msft-main # Adjust if needed - push: - branches: - - mitchzhu/clippy + - msft-main jobs: binskim: @@ -73,7 +70,7 @@ jobs: echo "Error: kata-agent binary not found!" exit 1 fi - binskim analyze "$KATA_AGENT_PATH" --level Error --kind "Pass;Fail" > binskim_agent + binskim analyze "$KATA_AGENT_PATH" --level Error --kind "Pass;Fail" > binskim_result_agent #- name: Scan runtime binary @@ -83,7 +80,7 @@ jobs: # echo "Error: kata-runtime binary not found!" # exit 1 # fi - # binskim analyze "$KATA_RUNTIME_PATH" --level Error --kind "Pass;Fail" > binskim_runtime + # binskim analyze "$KATA_RUNTIME_PATH" --level Error --kind "Pass;Fail" > binskim_result_runtime - name: Scan tardev-snapshotter binary run: | @@ -92,7 +89,7 @@ jobs: echo "Error: tardev-snapshotter binary not found!" exit 1 fi - binskim analyze "$TARDEV_SNAPSHOTTER_PATH" --level Error --kind "Pass;Fail" > binskim_tardev + binskim analyze "$TARDEV_SNAPSHOTTER_PATH" --level Error --kind "Pass;Fail" > binskim_result_tardev - name: Scan overlay binary run: | @@ -101,23 +98,23 @@ jobs: echo "Error: kata-overlay binary not found!" exit fi - binskim analyze "$OVERLAY_PATH" --level Error --kind "Pass;Fail" > binskim_overlay + binskim analyze "$OVERLAY_PATH" --level Error --kind "Pass;Fail" > binskim_result_overlay # Validate BinSkim result - name: Validate BinSkim result run: | - for file in binskim_agent binskim_tardev binskim_overlay; do + for file in binskim_result_agent binskim_result_tardev binskim_result_overlay; do if [ ! -f "$file" ]; then echo "Error: $file was not generated." exit 1 fi - echo "Scanning Binary: ${file}" + echo "Validating: ${file}" cat "$file" if grep -qi "fail" "$file"; then - echo "Error: Failures detected in $file." + echo "❌ Error: Failures detected in $file." exit 1 fi echo "--------------------------- End-------------------------" done - echo "All BinSkim results are passing with no failures." + echo "✅ All BinSkim results are passing with no failures." diff --git a/.github/workflows/clippy.yaml b/.github/workflows/clippy.yaml index 16bb51f7db51..52ed1549d9e4 100644 --- a/.github/workflows/clippy.yaml +++ b/.github/workflows/clippy.yaml @@ -3,10 +3,7 @@ name: Rust Clippy Check on: pull_request: branches: - - msft-main # Adjust if needed - push: - branches: - - mitchzhu/clippy # Run the workflow when pushing to this branch + - msft-main jobs: clippy: diff --git a/.github/workflows/nancy.yaml b/.github/workflows/nancy.yaml index 2e97ecd46352..555d8ca24dd9 100644 --- a/.github/workflows/nancy.yaml +++ b/.github/workflows/nancy.yaml @@ -3,10 +3,7 @@ name: Go Dependency Security Check (Nancy) on: pull_request: branches: - - msft-main # Adjust if needed - push: - branches: - - mitchzhu/clippy + - msft-main jobs: nancy: