Update .gitea/workflows/ci.yml #16

Merged
kpcto merged 1 commits from kpcto-patch-1 into main 2026-08-26 17:57:21 +00:00
+6 -5
View File
@@ -11,8 +11,12 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Enable pnpm
run: corepack enable # pnpm ships with Node 20 via corepack
- name: Install dependencies
run: pnpm install
- name: Run test suite - name: Run test suite
run: npm test run: pnpm test
gitleaks: gitleaks:
name: Secret scan (gitleaks) name: Secret scan (gitleaks)
@@ -21,10 +25,7 @@ jobs:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Install gitleaks - name: Install gitleaks
run: | run: |
curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz -o gitleaks.tar.gz curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.30.1/gitleaks_8.30.1_linux_arm64.tar.gz -o gitleaks.tar.gz
tar -xzf gitleaks.tar.gz gitleaks tar -xzf gitleaks.tar.gz gitleaks
# `gitleaks detect` exits non-zero on any finding, so this step fails the
# build on any secret hit. `--no-git` scans the checked-out tree only;
# `--redact` masks matched secrets in the log output.
- name: Run gitleaks (fail on any hit) - name: Run gitleaks (fail on any hit)
run: ./gitleaks detect --source . --no-git --redact -v run: ./gitleaks detect --source . --no-git --redact -v