Some checks failed
Dev CI / Backend — Lint (push) Successful in 1m4s
Dev CI / Security gate (push) Failing after 1m36s
Dev CI / Backend — Unit Tests (push) Successful in 1m7s
Dev CI / Frontend — Lint & Type-check (push) Successful in 1m51s
Dev CI / Frontend — Unit Tests (push) Successful in 1m22s
Dev CI / Notify Failure (push) Has been skipped
32 lines
1.1 KiB
YAML
32 lines
1.1 KiB
YAML
name: Security gate
|
|
description: Dependency, secrets, infrastructure and workflow checks for Gitea 1.22.
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- uses: ./.gitea/actions/setup-node
|
|
- name: Install Trivy
|
|
shell: bash
|
|
run: |
|
|
trivy_bin=$(bash scripts/ci/install-tool.sh trivy)
|
|
"$trivy_bin" --version
|
|
- name: Validate workflows and deployment checks
|
|
shell: bash
|
|
run: |
|
|
actionlint_bin=$(bash scripts/ci/install-tool.sh actionlint)
|
|
ACTIONLINT_BIN="$actionlint_bin" bash scripts/ci/validate-workflows.sh
|
|
- name: Audit dependencies, secrets and infrastructure
|
|
shell: bash
|
|
run: bash scripts/ci/security-audit.sh
|
|
- name: Show security results
|
|
if: always()
|
|
shell: bash
|
|
run: python3 scripts/ci/summarize-security.py
|
|
- name: Save security reports on Gitea
|
|
if: always()
|
|
uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol
|
|
with:
|
|
name: security-reports
|
|
path: ${{ runner.temp }}/security-reports/*.json
|
|
retention-days: 7
|
|
if-no-files-found: error
|