Update .gitea/workflows/ci.yml
This commit is contained in:
@@ -11,8 +11,12 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Enable pnpm
|
||||
run: corepack enable # pnpm ships with Node 20 via corepack
|
||||
- name: Install dependencies
|
||||
run: pnpm install
|
||||
- name: Run test suite
|
||||
run: npm test
|
||||
run: pnpm test
|
||||
|
||||
gitleaks:
|
||||
name: Secret scan (gitleaks)
|
||||
@@ -21,10 +25,7 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Install gitleaks
|
||||
run: |
|
||||
curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz -o gitleaks.tar.gz
|
||||
curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_arm64.tar.gz -o gitleaks.tar.gz
|
||||
tar -xzf gitleaks.tar.gz gitleaks
|
||||
# `gitleaks detect` exits non-zero on any finding, so this step fails the
|
||||
# build on any secret hit. `--no-git` scans the checked-out tree only;
|
||||
# `--redact` masks matched secrets in the log output.
|
||||
- name: Run gitleaks (fail on any hit)
|
||||
run: ./gitleaks detect --source . --no-git --redact -v
|
||||
Reference in New Issue
Block a user