name: Security gate description: Dependency, secrets, infrastructure and workflow checks for Gitea 1.22. runs: using: composite steps: - uses: ./.gitea/actions/setup-node - uses: ./.gitea/actions/setup-trivy - name: Validate workflows and deployment checks shell: bash run: | actionlint_bin=$(bash scripts/ci/install-tool.sh actionlint) ACTIONLINT_BIN="$actionlint_bin" bash scripts/ci/validate-workflows.sh - name: Audit dependencies, secrets and infrastructure shell: bash run: bash scripts/ci/security-audit.sh - name: Save security reports on Gitea if: always() uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol with: name: security-reports path: ${{ runner.temp }}/security-reports/*.json retention-days: 7 if-no-files-found: error