cifuzz.yml 1.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253
  1. name: CIFuzz
  2. on:
  3. pull_request:
  4. branches: ["master"]
  5. concurrency:
  6. group: ${{ github.workflow }}-${{ github.ref }}
  7. cancel-in-progress: true
  8. permissions: {}
  9. jobs:
  10. fuzz:
  11. runs-on: ubuntu-latest
  12. permissions:
  13. security-events: write
  14. strategy:
  15. fail-fast: false
  16. matrix:
  17. sanitizer: ["address", "memory", "undefined"]
  18. steps:
  19. - uses: actions/checkout@v6
  20. - name: build fuzzers (${{ matrix.sanitizer }})
  21. id: build
  22. uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master
  23. with:
  24. oss-fuzz-project-name: coturn
  25. language: c
  26. sanitizer: ${{ matrix.sanitizer }}
  27. - name: run fuzzers (${{ matrix.sanitizer }})
  28. uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master
  29. with:
  30. oss-fuzz-project-name: coturn
  31. language: c
  32. sanitizer: ${{ matrix.sanitizer }}
  33. fuzz-seconds: 600
  34. output-sarif: true
  35. - name: upload crash
  36. uses: actions/upload-artifact@v6
  37. with:
  38. name: ${{ matrix.sanitizer }}_artifacts
  39. path: ./out/artifacts
  40. if: ${{ failure() && steps.build.outcome == 'success' }}
  41. - name: upload sarif
  42. uses: github/codeql-action/upload-sarif@v4
  43. with:
  44. sarif_file: cifuzz-sarif/results.sarif
  45. if: ${{ always() && steps.build.outcome == 'success' }}