Some checks failed
Dev CI / Backend — Lint (push) Failing after 1m5s
Dev CI / Backend — Unit Tests (push) Has been skipped
Dev CI / Security gate (push) Failing after 1m20s
Dev CI / Frontend — Lint & Type-check (push) Successful in 1m46s
Dev CI / Frontend — Unit Tests (push) Successful in 1m21s
Dev CI / Notify Failure (push) Has been skipped
48 lines
2.3 KiB
Bash
48 lines
2.3 KiB
Bash
#!/usr/bin/env bash
|
|
# Pinned Linux tools for either native architecture; never execute a foreign binary.
|
|
set -euo pipefail
|
|
tool="${1:?Usage: install-tool.sh trivy|actionlint|hcloud [--print-source]}"
|
|
[[ "$(uname -s)" == Linux ]] || { echo 'CI tools require Linux' >&2; exit 1; }
|
|
case "$(uname -m)" in
|
|
x86_64|amd64) arch=amd64 ;;
|
|
aarch64|arm64) arch=arm64 ;;
|
|
*) echo 'Unsupported runner architecture' >&2; exit 1 ;;
|
|
esac
|
|
case "$tool:$arch" in
|
|
trivy:amd64)
|
|
url=https://github.com/aquasecurity/trivy/releases/download/v0.74.0/trivy_0.74.0_Linux-64bit.tar.gz
|
|
sha=2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a ;;
|
|
trivy:arm64)
|
|
url=https://github.com/aquasecurity/trivy/releases/download/v0.74.0/trivy_0.74.0_Linux-ARM64.tar.gz
|
|
sha=b94ce1976bbf3c15b514b605ee88be7c6d94a29be2302847ff01cb794d47aad5 ;;
|
|
actionlint:amd64)
|
|
url=https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
|
|
sha=8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 ;;
|
|
actionlint:arm64)
|
|
url=https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_arm64.tar.gz
|
|
sha=325e971b6ba9bfa504672e29be93c24981eeb1c07576d730e9f7c8805afff0c6 ;;
|
|
hcloud:amd64)
|
|
url=https://github.com/hetznercloud/cli/releases/download/v1.49.0/hcloud-linux-amd64.tar.gz
|
|
sha=dc6e5b0e6eaf9ef2baa5473a3eb49a11e80e72cdf2a01fdf7b0af975410e79cc ;;
|
|
hcloud:arm64)
|
|
url=https://github.com/hetznercloud/cli/releases/download/v1.49.0/hcloud-linux-arm64.tar.gz
|
|
sha=183dabe0a03b3eb7b93f8d2f2cf91c478de57f9412f189866eda0fdde7baf88c ;;
|
|
*) echo "Unsupported tool: $tool" >&2; exit 1 ;;
|
|
esac
|
|
if [[ "${2:-}" == --print-source ]]; then
|
|
printf '%s\n%s\n' "$url" "$sha"
|
|
exit 0
|
|
fi
|
|
install_dir="${RUNNER_TEMP:?}/ci-tools/$tool"
|
|
mkdir -p "$install_dir"
|
|
echo "Installing $tool for Linux/$arch" >&2
|
|
curl --fail --silent --show-error --location --retry 3 --max-time 120 \
|
|
"$url" --output "$install_dir/archive.tar.gz"
|
|
echo "$sha $install_dir/archive.tar.gz" | sha256sum --check --strict >&2
|
|
tar -xzf "$install_dir/archive.tar.gz" -C "$install_dir" "$tool"
|
|
chmod +x "$install_dir/$tool"
|
|
printf '%s\n' "$install_dir" >> "${GITHUB_PATH:?}"
|
|
# Older act_runner releases can keep the container PATH ahead of add-path entries.
|
|
printf 'PATH=%s:%s\n' "$install_dir" "$PATH" >> "${GITHUB_ENV:?}"
|
|
printf '%s\n' "$install_dir/$tool"
|