-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathintune-script-gate.yml
More file actions
103 lines (92 loc) · 4.33 KB
/
Copy pathintune-script-gate.yml
File metadata and controls
103 lines (92 loc) · 4.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
# IntuneScriptLab gate for a repository of Intune scripts. Copy to .github/workflows/ and set the
# paths. On every pull request that touches a script it runs the analysis the way Intune will run
# the scripts, annotates the scripts under the paths you set with the findings, writes a job summary and fails on
# errors. The optional second job runs the runtime harness on a Windows runner.
#
# Where the module comes from: a copy checked into the repository when ISL_MODULE_PATH points at
# its manifest (the copy is used as it is, never a Gallery version behind it), otherwise the
# PowerShell Gallery.
name: Intune script gate
on:
pull_request:
paths:
- '**.ps1'
push:
branches: [main]
paths:
- '**.ps1'
permissions:
contents: read
# Needed only for the SARIF upload below
security-events: write
env:
# Folders holding the scripts: remediations, platform scripts, Win32 detection and requirement
# scripts. Folder and file names tell the analysis what each script is (Remediations\<name>\
# Detect.ps1, Win32\<app>\Detect.ps1, PlatformScripts\*.ps1); a directive comment overrides.
SCRIPT_PATHS: ./Intune
# Error fails the build; Warning is stricter; None reports only
FAIL_ON: Error
# A checked-in copy of the module, e.g. ./Tools/IntuneScriptLab/IntuneScriptLab.psd1; empty
# installs the module from the PowerShell Gallery instead
ISL_MODULE_PATH: ''
# Also publish the findings to code scanning (Security tab, PR checks). Code scanning is free on
# public repositories and needs GitHub Advanced Security on private ones.
UPLOAD_SARIF: 'false'
jobs:
analyze:
name: Analyze Intune scripts
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- name: Install IntuneScriptLab from the Gallery
if: env.ISL_MODULE_PATH == ''
shell: pwsh
run: Install-PSResource -Name IntuneScriptLab -TrustRepository -Scope CurrentUser
- name: Analyze
shell: pwsh
run: |
# The gate script sits in the module's Examples folder and imports the module beside it
$manifest = if ($env:ISL_MODULE_PATH) { (Resolve-Path $env:ISL_MODULE_PATH).Path }
else {
(Get-Module -Name IntuneScriptLab -ListAvailable | Sort-Object Version -Descending |
Select-Object -First 1).Path
}
$gate = Join-Path (Split-Path $manifest -Parent) 'Examples\Invoke-IntuneScriptGate.ps1'
$paths = $env:SCRIPT_PATHS -split ',' | ForEach-Object { $_.Trim() }
& $gate -Path $paths -FailOn $env:FAIL_ON -SarifPath "$env:RUNNER_TEMP\intune-script-lab.sarif"
- name: Upload SARIF to code scanning
if: always() && env.UPLOAD_SARIF == 'true'
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ runner.temp }}/intune-script-lab.sarif
category: IntuneScriptLab
# Runtime checks: real Windows PowerShell 5.1 launches the way the agent does them, from a
# Pester suite built on Examples/IntuneScripts.Tests.ps1.template. Needs Windows; SYSTEM-context
# tests are skipped on a hosted runner (no elevation for a scheduled task).
runtime:
name: Run the scripts as Intune would
runs-on: windows-latest
needs: analyze
if: false # switch on once IntuneScripts.Tests.ps1 exists next to the scripts
steps:
- uses: actions/checkout@v4
- name: Install Pester, and IntuneScriptLab unless a checked-in copy is used
shell: pwsh
run: |
$modules = @('Pester')
if (-not $env:ISL_MODULE_PATH) { $modules += 'IntuneScriptLab' }
Install-PSResource -Name $modules -TrustRepository -Scope CurrentUser
- name: Invoke-Pester
shell: pwsh
run: |
# The suite's BeforeAll does Import-Module IntuneScriptLab; a checked-in copy is put on
# the module path so that line finds it
if ($env:ISL_MODULE_PATH) {
$root = Split-Path (Split-Path (Resolve-Path $env:ISL_MODULE_PATH).Path -Parent) -Parent
$env:PSModulePath = "$root$([IO.Path]::PathSeparator)$env:PSModulePath"
}
$config = New-PesterConfiguration
$config.Run.Path = @($env:SCRIPT_PATHS -split ',' | ForEach-Object { $_.Trim() })
$config.Run.Exit = $true
$config.Output.Verbosity = 'Detailed'
Invoke-Pester -Configuration $config