name: Security gate description: Dependency, secrets, infrastructure and workflow checks for Gitea 1.22. runs: using: composite steps: - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: node-version: '22' - uses: ./.gitea/actions/setup-trivy - name: Validate workflows and deployment checks shell: bash run: | archive="$RUNNER_TEMP/actionlint.tar.gz" curl --fail --silent --show-error --location --retry 3 --max-time 120 \ https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz \ --output "$archive" echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 $archive" | sha256sum --check --strict tar -xzf "$archive" -C "$RUNNER_TEMP" actionlint ACTIONLINT_BIN="$RUNNER_TEMP/actionlint" bash scripts/ci/validate-workflows.sh - name: Audit dependencies, secrets and infrastructure shell: bash run: bash scripts/ci/security-audit.sh - name: Save security reports on Gitea if: always() uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol with: name: security-reports path: ${{ runner.temp }}/security-reports/*.json retention-days: 7 if-no-files-found: error