mirror of
https://github.com/laramies/theHarvester.git
synced 2026-09-29 04:54:53 +02:00
Preserve provider outcome release notes alongside the HTTP proxy wording. Keep the dev domain glossary and carry the master HTTP-only proxy policy into its relocated architecture guide. Retain RocketReach cancellation coverage while removing the obsolete global dependency stub. Align provider lifecycle regressions with the master session-construction boundary: construction ValueError is normalized to transport-error, while cancellation, lifecycle RuntimeError, and teardown ValueError still propagate.
159 lines
5.3 KiB
YAML
159 lines
5.3 KiB
YAML
name: Release validation
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
run_live:
|
|
description: Run bounded P0 provider checks against mozilla.org
|
|
required: true
|
|
default: false
|
|
type: boolean
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
python-ci:
|
|
uses: ./.github/workflows/theHarvester.yml
|
|
|
|
harvestview-e2e:
|
|
uses: ./.github/workflows/harvestview-e2e.yml
|
|
|
|
container-smoke:
|
|
uses: ./.github/workflows/harvestview-container.yml
|
|
|
|
package-smoke:
|
|
needs: python-ci
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Check out repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
python-version: '3.14'
|
|
enable-cache: true
|
|
cache-dependency-glob: uv.lock
|
|
|
|
- name: Build distributions
|
|
run: uv build --out-dir release-dist
|
|
|
|
- name: Verify installed distributions
|
|
run: |
|
|
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
|
|
sdist_path="$(find release-dist -maxdepth 1 -name '*.tar.gz' -print -quit)"
|
|
test -n "$wheel_path"
|
|
test -n "$sdist_path"
|
|
uv run --isolated --no-project --with "$wheel_path" theHarvester --help
|
|
uv run --isolated --no-project --with "$wheel_path" harvestview --help
|
|
uv run --isolated --no-project --with "$sdist_path" theHarvester --help
|
|
|
|
- name: Upload release distributions
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: release-distributions-${{ github.sha }}
|
|
path: release-dist/*
|
|
if-no-files-found: error
|
|
retention-days: 7
|
|
|
|
live-provider-tests:
|
|
if: ${{ inputs.run_live }}
|
|
needs: [python-ci, harvestview-e2e, container-smoke, package-smoke]
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
env:
|
|
SMOKE_TEST_DOMAIN: mozilla.org
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Check out repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
python-version: '3.14'
|
|
enable-cache: true
|
|
cache-dependency-glob: uv.lock
|
|
|
|
- name: Install dependencies
|
|
run: uv sync --all-groups --frozen
|
|
|
|
- name: Validate P0 provider test contract
|
|
run: |
|
|
uv run python -c \
|
|
'import sys; from theHarvester.lib.source_catalog import ActivityClass, get_source_spec; assert all(get_source_spec(name).activity is ActivityClass.PASSIVE for name in sys.argv[1:])' \
|
|
certspotter otx thc
|
|
|
|
- name: Run opt-in live provider tests
|
|
run: |
|
|
uv run pytest --run-live-network -m live_network -q \
|
|
tests/discovery/test_certspotter.py::TestCertspotterSearch::test_api \
|
|
tests/discovery/test_otx.py::TestOtx::test_api \
|
|
tests/discovery/test_thc.py::TestThcApi
|
|
|
|
live-cli-smoke:
|
|
if: ${{ inputs.run_live }}
|
|
needs: [python-ci, harvestview-e2e, container-smoke, package-smoke]
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
source:
|
|
- certspotter
|
|
- crtsh
|
|
- duckduckgo
|
|
- hackertarget
|
|
- otx
|
|
- rapiddns
|
|
- urlscan
|
|
- yahoo
|
|
env:
|
|
SMOKE_TEST_DOMAIN: mozilla.org
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
python-version: '3.14'
|
|
enable-cache: true
|
|
|
|
- name: Download release distributions
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: release-distributions-${{ github.sha }}
|
|
path: release-dist
|
|
|
|
- name: Verify source is P0
|
|
run: |
|
|
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
|
|
test -n "$wheel_path"
|
|
uv run --isolated --no-project --with "$wheel_path" python -c \
|
|
'import sys; from theHarvester.lib.source_catalog import ActivityClass, get_source_spec; assert get_source_spec(sys.argv[1]).activity is ActivityClass.PASSIVE' \
|
|
'${{ matrix.source }}'
|
|
|
|
- name: Run installed-wheel P0 CLI smoke
|
|
run: |
|
|
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
|
|
uv run --isolated --no-project --with "$wheel_path" \
|
|
theHarvester -d "$SMOKE_TEST_DOMAIN" -b '${{ matrix.source }}' -l 10 -q
|