name: CI on: pull_request: push: branches: [main] jobs: test: name: Run tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Run test suite run: npm test gitleaks: name: Secret scan (gitleaks) runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install gitleaks run: | curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz -o gitleaks.tar.gz tar -xzf gitleaks.tar.gz gitleaks # `gitleaks detect` exits non-zero on any finding, so this step fails the # build on any secret hit. `--no-git` scans the checked-out tree only; # `--redact` masks matched secrets in the log output. - name: Run gitleaks (fail on any hit) run: ./gitleaks detect --source . --no-git --redact -v