Commit Graph

116 Commits

Author SHA1 Message Date
Stephan Renatus afe58b45be ci/pull-request: change action used for wasm filter (#5365)
Fixing recent failures we've had with the other action.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-11-07 14:56:58 +01:00
Stephan Renatus 1cf2c781b6 workflow/post-tag: fix typo (#5350)
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-11-03 09:39:49 +01:00
dependabot[bot] c2c9e536fc build(deps): bump aquasecurity/trivy-action from 0.7.1 to 0.8.0 (#5331) 2022-11-01 11:45:53 +00:00
Stephan Renatus a6bc34d64d ci(pull-request): setup-opa@v1 -> setup-opa@v2 (#5302)
Resolves https://github.com/open-policy-agent/setup-opa/issues/18 for the usage in this repo.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-10-25 11:53:35 +02:00
Stephan Renatus 482769dd12 nightly: address recent findings, update trivyignore (#5287)
This is a bit of a bag of a few smaller things:

* workflows/nightly: skip imported gqlparser package.json
   It is not used anywhere.

* .trivyignore: remove docker CVE
   This has been bumped away when updating ORAS.

* website/livescripts: bump minimatch
   This also updated the lockfile version... I think that's OK.

* workflows/pull-request: don't setup opa for docker image smoke test
* address netlify ignore script failure on large output

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-10-21 12:06:38 +02:00
Stephan Renatus 9677a09d9e workflow: use GITHUB_OUTPUT, not ::set-output (#5245)
https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-10-13 14:00:00 +02:00
dependabot[bot] a226f4f1ed build(deps): bump tj-actions/changed-files from 32.0.0 to 32.1.0 (#5244)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 32.0.0 to 32.1.0.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v32.0.0...v32.1.0)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-10-13 13:49:33 +02:00
dependabot[bot] 4ea5c0f1b9 build(deps): bump tj-actions/changed-files from 29.0.9 to 32.0.0 (#5215)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 29.0.9 to 32.0.0.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v29.0.9...v32.0.0)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-10-06 14:04:07 +02:00
dependabot[bot] 584caa3cfe build(deps): bump tj-actions/changed-files from 29.0.7 to 29.0.9 (#5158) 2022-09-20 11:41:49 +00:00
dependabot[bot] 91f641be2c build(deps): bump tj-actions/changed-files from 29.0.5 to 29.0.7 (#5138) 2022-09-14 11:44:40 +00:00
dependabot[bot] 478812c408 build(deps): bump tj-actions/changed-files from 29.0.4 to 29.0.5 (#5132) 2022-09-13 11:41:43 +00:00
Stephan Renatus 31518a1ee0 ci(nightly): send notifications for trivy and govulncheck checks (#5116)
Since one of them had been failing for two weeks, unnoticed...

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-09-09 14:12:03 +02:00
dependabot[bot] 813a234f3c build(deps): bump tj-actions/changed-files from 29.0.3 to 29.0.4 (#5113) 2022-09-08 12:12:09 +00:00
Stephan Renatus 7a63889ed1 ci: try govulncheck from nightly (#5103)
See https://go.dev/security/vuln/ for details.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-09-08 09:14:02 +02:00
dependabot[bot] a2d855f3d9 build(deps): bump tj-actions/changed-files from 29.0.2 to 29.0.3 (#5092)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 29.0.2 to 29.0.3.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v29.0.2...v29.0.3)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-09-05 18:04:01 +02:00
Stephan Renatus 287c9b9923 ci: re-enable wasm lib tests (#5076)
It had slipped my mind that those need docker, too. Previously, I've disabled
docker for those tests to avoid having them rebuild their wasm artifacts.

The wasm/Makefile change is superficial, and just meant to ensure we run this
test while the PR is WIP. Changes to .github/workflow/* alone won't trigger the
wasm tests.
 
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-09-01 09:40:57 +02:00
dependabot[bot] 82d2264fbf build(deps): bump tj-actions/changed-files from 29.0.1 to 29.0.2 (#5062)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 29.0.1 to 29.0.2.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v29.0.1...v29.0.2)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-29 13:28:40 +02:00
dependabot[bot] 27521bb6e1 build(deps): bump tj-actions/changed-files from 29.0.0 to 29.0.1 (#5055)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 29.0.0 to 29.0.1.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v29.0.0...v29.0.1)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-26 13:25:49 +02:00
dependabot[bot] 815fc424c6 build(deps): bump tj-actions/changed-files from 28.0.0 to 29.0.0 (#5047)
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 28.0.0 to 29.0.0.
- [Release notes](https://github.com/tj-actions/changed-files/releases)
- [Changelog](https://github.com/tj-actions/changed-files/blob/main/HISTORY.md)
- [Commits](https://github.com/tj-actions/changed-files/compare/v28.0.0...v29.0.0)

---
updated-dependencies:
- dependency-name: tj-actions/changed-files
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-24 14:03:05 +02:00
Stephan Renatus 70e90bdbbb ci: remove quick-fuzz, guard wasm tests on changed files, limit concurrency (#5030)
* ci: remove quick-fuzz, guard wasm tests on changed files

This is a first step into running less things all the time that don't need to
be run all the time.

It's a heuristic, and as such fallible: there could always be changes that
break something in the wasm code path, because I have forgotten that there's a
dependency of some sort.

Removing the quick-fuzz target, it's never brought any issues up; and still
runs in nightly tests.

* ci: cancel previous run for PRs

From https://stackoverflow.com/a/72408109/993018.

* ci: avoid rebuilding wasm

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-08-22 16:28:45 +02:00
Stephan Renatus 1fca607758 ci: ubuntu 18.04 -> 22.04 (#5031)
ubuntu-18.04 was causing our builds to break, in a scheduled brownout.

All references to either ubuntu-latest or ubuntu-18.04 are now ubuntu-22.04.
(I figured it's better to control the version in all places.)

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-08-22 15:07:28 +02:00
dependabot[bot] 40b1bad429 build(deps): bump aquasecurity/trivy-action from 0.7.0 to 0.7.1 (#5024)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.7.0 to 0.7.1.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.7.0...0.7.1)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-19 13:20:17 +02:00
dependabot[bot] 47c8256b60 build(deps): bump aquasecurity/trivy-action from 0.6.2 to 0.7.0 (#5017)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.6.2 to 0.7.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.6.2...0.7.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-17 13:20:33 +02:00
Stephan Renatus 27274e08b6 build: use go 1.19, drop go 1.16 (#5013)
With this, we'll build our container images and binaries using golang 1.19.

Also, the go.mod version stanza is increased, letting us use go1.17+ features.

I had to run

    go mod tidy -go=1.16 && go mod tidy -go=1.17

to get rid of `go mod tidy` related messages, and ran `go mod vendor`
afterwards.

* prometheus: adjust tests for new go1.19 metrics

Note that the new metrics only appear when using the Go runtime of 1.19. So,
we do the same we've done before when 1.17 brought in new metrics: add them
to the tests, and use build flags to not run the tests in the previous versions.

When the bump of github.com/prometheus/go_client to 1.13.0 was merged, it was
properly tested with all of 1.17 and 1.18. So, the previously expected metrics
should be there when using OPA from 1.17 or 1.18.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-08-15 18:05:55 +02:00
dependabot[bot] b03c188907 build(deps): bump aquasecurity/trivy-action from 0.6.1 to 0.6.2 (#4969)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.6.1 to 0.6.2.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.6.1...0.6.2)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-11 12:31:46 -04:00
dependabot[bot] eff91f755c build(deps): bump aquasecurity/trivy-action from 0.6.0 to 0.6.1 (#4941) 2022-07-27 11:33:42 +00:00
Stephan Renatus c981cc9bd0 ci(nightly): various trivy-related tweaks (#4935)
1. only check the edge-static image

   There are a bunch of libc-related findings that are hard to address, and
   likely not relevant for us: for example, Go will not use glibc's regexp
   engine, even if linked against libc.

2. pull the image before checking it

   I've noticed locally that `trivy image` will just use whatever image it
   finds under the mentioned tag. So we pull first to ensure that we actually
   scan the right 'edge' image.

3. split jobs

   Before, the scan-repo step wouldn't ever happen if scan-image failed. Let's
   do them both all the time instead.

4. for the repo scan, ignore go.mod files of the dependencies -- there's little
   we can do about, say, grpc referencing a vulnerable yaml.v2 dep in its
   go.mod. And there should also be little harm in it, since we're using a more
   recent version in our go.mod.

5. Updated .trivyignore with recent, new, findings.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-07-25 12:00:53 +02:00
dependabot[bot] 9f9fbb91e9 build(deps): bump aquasecurity/trivy-action from 0.5.1 to 0.6.0 (#4929)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.5.1 to 0.6.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.5.1...0.6.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-22 15:04:04 +02:00
Stephan Renatus eef861dec6 CI: remove trivy from PRs, add CVE-2022-1996 to ignores (#4867)
This is breaking contributions when there is something new in trivy's
databases. That's unfortunate, and will be turned off by this commit.

We're still running the checks nightly, and that's good enough for raising the
maintainers' attention.

* .trivyignore: add CVE-2022-1996

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-07-11 09:45:27 +02:00
dependabot[bot] 2f169d9c13 build(deps): bump aquasecurity/trivy-action from 0.5.0 to 0.5.1 (#4833) 2022-06-30 11:40:32 +00:00
dependabot[bot] 0efaa0534e build(deps): bump aquasecurity/trivy-action from 0.4.1 to 0.5.0 (#4811)
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.4.1 to 0.5.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](https://github.com/aquasecurity/trivy-action/compare/0.4.1...0.5.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-06-23 16:38:59 +02:00
Juan Antonio Osorio f41f84d1f9 ci: Use Trivy for vulnerability scans (#4804)
This uses Trivy to scan both the Git repo, as well as the generated
container image for vulnerabilities. It leverages Trivy's GitHub action
[1]. Currently, it's set to alert on `CRITICAL` and `HIGH`
vulnerabilities only.

[1] https://github.com/aquasecurity/trivy-action

This adds a section in the developer docs, as well as comments on the GitHub workflows.

Signed-off-by: Juan Antonio Osorio <juan.osoriorobles@eu.equinix.com>
2022-06-23 08:17:28 +02:00
Peter ONeill 45343c88c4 Updating the feature request questions (#4784)
Signed-off-by: Peter ONeill <peteroneilljr@gmail.com>
2022-06-20 11:04:02 +02:00
Stephan Renatus 9a6bdaf9c4 ci/npm-opa-wasm: remove (#4758)
To be brought back eventually; for now, it is just randomly failing.

We haven't been touching the Wasm interface in a while, so this test
isn't urgently needed these days.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-06-09 11:46:51 +02:00
Stephan Renatus b271372338 build: add v0.41.0 builtin_metadata manually, pin npm-opa-wasm in CI (#4753)
* builtin_metadata: add v0.41.0 manually

We'll figure out how to do this in the release process, but for now, this
is enough to not have the builtin_metadata.json change appear in each PR.

* ci: pin last release of npm-opa-wasm

This is temporary; I don't want to deal with this right now.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-06-08 10:28:24 +02:00
dependabot[bot] 4b2e980c86 build(deps): bump docker/setup-buildx-action from 1 to 2 (#4669)
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 1 to 2.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-05-06 14:07:10 +02:00
dependabot[bot] 858acdbf6f build(deps): bump docker/setup-qemu-action from 1 to 2 (#4668) 2022-05-06 11:37:41 +00:00
dependabot[bot] f27360c0b9 build(deps): bump github/codeql-action from 1 to 2 (#4621)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 13:31:42 +02:00
Naveen a2595c1e4f workflow: no content permissions for GitHub action 'post-release' (#4579)
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

See also:
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
https://securitylab.github.com/research/github-actions-preventing-pwn-requests/

NOTE(sr): This is a first step, there are probably more opportunities for restricting permissions
in our workflows.

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
2022-04-20 09:15:50 +02:00
dependabot[bot] 6c2aad0fff build(deps): bump actions/download-artifact from 2 to 3 (#4575) 2022-04-11 12:07:03 +00:00
dependabot[bot] c9606c07a4 build(deps): bump actions/setup-go from 2 to 3 (#4574) 2022-04-11 11:54:09 +00:00
dependabot[bot] d618ba3142 build(deps): bump actions/upload-artifact from 2 to 3 (#4573) 2022-04-11 11:40:44 +00:00
Stephan Renatus a940cb636e ci: misc test-related fixes (#4549)
* topdown: fix TestRego: run for all go versions, excluding the x509 error

That error has a different message on go1.16.

The previous attempt to exclude them from running caused _all tests_
to not be run.

* topdown_test/TestTopDownQueryCancellationEvery: up wait time for macos flakey tests

We've often seen this fail with "0 notes". Waiting for 10x the time
we previous waited for still seems to do the trick but should
hopefully remove the amount of failures we see in CE because of
slow macos runners.

* ci: don't run wasm build again in compat builds

The build is docker-based, and doesn't differ at all if run from a
different version of golang. So instead of re-building it in the
separate matrix jobs, we'll use the artifacts downloaded from the
artifact build job.

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-04-05 13:57:04 +02:00
Stephan Renatus 6673f3e81a ci: fix rego check (#4532)
* build/policies: format using 0.39.0
* workflow/pull-request: use edge opa for rego PR checks

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-04-01 09:31:13 +02:00
Stephan Renatus 14c2906afb ci: remove go-fuzz, use native go 1.18 fuzzer
Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-03-28 07:24:21 +02:00
Stephan Renatus d2914c0d54 build: bump golang: 1.17 -> 1.18
No change to go.mod's `go` stanza, so no changes in code compatibility.

However, it's used for building our docker images and release
binaries, and for fuzz testing in our nightly workflow.

Some test-related changes with the dns lookup built-in function's
error handling; and the hardcoded signature. Running

    go test ./topdown -run TestTopdownJWTEncodeSignECWithSeedReturnsSameSignature -count 10000

makes me believe that for whatever reason the signature changed,
it's at least stable.

topdown/http_test: Test-only change to accomodate this change in Go (https://go.dev/doc/go1.18):

    Certificate.Verify now uses platform APIs to verify certificate
    validity on macOS and iOS when it is called with a nil
    VerifyOpts.Roots or when using the root pool returned from
    SystemCertPool.

We're keeping the old message for go <= 1.17; in a silly-simple way.

Also:

* ci: build and test two old golang version on macos|linux

  We'll drop golang 1.15, keep one unsupported version (1.16).

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-03-28 07:24:21 +02:00
Anders Eknert b023fd1607 cicd: verify logo name matches integration (#4441)
Signed-off-by: Anders Eknert <anders@eknert.com>
2022-03-17 07:06:56 +01:00
Anders Eknert d2684b995c Use gid=1000 in -rootless images (#4407)
Fixes #4380

Signed-off-by: Anders Eknert <anders@eknert.com>
2022-03-04 13:19:48 +01:00
dependabot[bot] cd36c744f4 build(deps): bump actions/checkout from 2 to 3 (#4395) 2022-03-02 11:36:40 +00:00
Stephan Renatus c4ab4b35c9 ast/parser: parse 'with' on 'some x in xs' expression (#4371)
Fixes #4226.

Also
* adds a YAML test to ensure that this works fine end-to-end.
* ci(pull-request): show input on failure

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2022-02-22 13:43:02 +01:00