31 lines
1.4 KiB
YAML
31 lines
1.4 KiB
YAML
name: Security gate
|
|
description: Dependency, secrets, infrastructure and workflow checks for Gitea 1.22.
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
|
|
with:
|
|
node-version: '22'
|
|
- uses: ./.gitea/actions/setup-trivy
|
|
- name: Validate workflows and deployment checks
|
|
shell: bash
|
|
run: |
|
|
archive="$RUNNER_TEMP/actionlint.tar.gz"
|
|
curl --fail --silent --show-error --location --retry 3 --max-time 120 \
|
|
https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz \
|
|
--output "$archive"
|
|
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 $archive" | sha256sum --check --strict
|
|
tar -xzf "$archive" -C "$RUNNER_TEMP" actionlint
|
|
ACTIONLINT_BIN="$RUNNER_TEMP/actionlint" bash scripts/ci/validate-workflows.sh
|
|
- name: Audit dependencies, secrets and infrastructure
|
|
shell: bash
|
|
run: bash scripts/ci/security-audit.sh
|
|
- name: Save security reports on Gitea
|
|
if: always()
|
|
uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol
|
|
with:
|
|
name: security-reports
|
|
path: ${{ runner.temp }}/security-reports/*.json
|
|
retention-days: 7
|
|
if-no-files-found: error
|