From d7740e3819d70bb77ed9919d3912e16a6dac7081 Mon Sep 17 00:00:00 2001 From: kpcto Date: Wed, 26 Aug 2026 17:56:07 +0000 Subject: [PATCH] Update .gitea/workflows/ci.yml --- .gitea/workflows/ci.yml | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 666af69..d61dba4 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -11,8 +11,12 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 + - name: Enable pnpm + run: corepack enable # pnpm ships with Node 20 via corepack + - name: Install dependencies + run: pnpm install - name: Run test suite - run: npm test + run: pnpm test gitleaks: name: Secret scan (gitleaks) @@ -21,10 +25,7 @@ jobs: - uses: actions/checkout@v4 - name: Install gitleaks run: | - curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz -o gitleaks.tar.gz + curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_arm64.tar.gz -o gitleaks.tar.gz tar -xzf gitleaks.tar.gz gitleaks - # `gitleaks detect` exits non-zero on any finding, so this step fails the - # build on any secret hit. `--no-git` scans the checked-out tree only; - # `--redact` masks matched secrets in the log output. - name: Run gitleaks (fail on any hit) - run: ./gitleaks detect --source . --no-git --redact -v + run: ./gitleaks detect --source . --no-git --redact -v \ No newline at end of file