aboutsummaryrefslogtreecommitdiff
path: root/.github/workflows
diff options
context:
space:
mode:
authorMarc André Tanner <mat@brain-dump.org>2021-04-20 21:21:37 +0200
committerMarc André Tanner <mat@brain-dump.org>2021-04-20 21:21:37 +0200
commitbcde0a768c843049e3c2a4ca32be0ad91e533148 (patch)
tree73f44fbc85787b12c13edd887ae69ebe0b0f2fba /.github/workflows
parentc45275951dd19db4a621656be66680d28fad8ae2 (diff)
downloadvis-bcde0a768c843049e3c2a4ca32be0ad91e533148.tar.gz
vis-bcde0a768c843049e3c2a4ca32be0ad91e533148.tar.xz
ci: verify coverity scan script before using it
Diffstat (limited to '.github/workflows')
-rw-r--r--.github/workflows/coverity-scan.yml9
1 files changed, 7 insertions, 2 deletions
diff --git a/.github/workflows/coverity-scan.yml b/.github/workflows/coverity-scan.yml
index 3a58aa3..48dfa9d 100644
--- a/.github/workflows/coverity-scan.yml
+++ b/.github/workflows/coverity-scan.yml
@@ -24,9 +24,14 @@ jobs:
- name: Download Coverity Build Tool
run: |
- wget -q https://scan.coverity.com/download/cxx/linux64 --post-data "token=$TOKEN&project=martanne/vis" -O cov-analysis-linux64.tar.gz
+ wget -q https://scan.coverity.com/download/cxx/linux64 --post-data "token=$TOKEN&project=martanne/vis" -O coverity_tool.tgz
+ wget -q https://scan.coverity.com/download/cxx/linux64 --post-data "token=$TOKEN&project=martanne/vis&md5=1" -O coverity_tool.md5
+ if ! (cat coverity_tool.md5; echo " coverity_tool.tgz") | md5sum -c --status; then
+ echo "Download checksum verification failed"
+ exit 1
+ fi
mkdir cov-analysis-linux64
- tar xzf cov-analysis-linux64.tar.gz --strip 1 -C cov-analysis-linux64
+ tar xzf coverity_tool.tgz --strip 1 -C cov-analysis-linux64
env:
TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}