stages:
- build
- test
build:
stage: build
image: python:3.9
script:
- python -m venv venv
- source venv/bin/activate
- pip install --upgrade pip
- pip install -r requirements.txt
test:
stage: test
image: python:3.9
dependencies:
- build
script:
- source venv/bin/activate
- pip install dependency-check # Example SCA tool
- dependency-check --scan . --format ALL --out reports # Run SCA
artifacts:
paths:
- reports
expire_in: 1 week
This GitLab CI/CD pipeline defines two sequential stages: build and test.
stages: This section declares the pipeline stages, ensuring they run in the defined order.
build:
stage: build: Assigns this job to the build stage.
image: python:3.9: Specifies that this job runs in a Docker container with the python:3.9 image.
script:: Contains the commands to execute:
- python -m venv venv: Creates a virtual environment named venv.
- source venv/bin/activate: Activates the virtual environment.
- pip install --upgrade pip: Upgrades the pip package installer.
- pip install -r requirements.txt: Installs all dependencies listed in the requirements.txt file.
test:
stage: test: Assigns this job to the test stage. This stage runs after the build stage completes successfully [2]. Note that this stage runs in a new environment [4].
image: python:3.9: Specifies that this job also runs in a new Docker container with the python:3.9 image.
dependencies: - build: Declares that this job depends on the successful completion of the build job.
script:: Contains the commands to execute:
- source venv/bin/activate: Activates the virtual environment (in the new container).
- pip install dependency-check: Installs the dependency-check tool, used here as an example for Software Component Analysis (SCA).
- dependency-check --scan . --format ALL --out reports: Runs the SCA tool to scan the project directory (.) and generate reports in all formats (ALL) to an output directory named reports.
artifacts: Defines files and directories to be stored after the job completes [3]:
paths: - reports: Specifies that the reports directory should be saved as an artifact.
expire_in: 1 week: Sets the expiration time for the artifacts to one week. These artifacts can be downloaded via the GitLab UI or API [3]. Artifacts can be used by later stages in the same pipeline or for merge request features [1].