Repository navigation
build(deps): bump brace-expansion from 5.0.9 to 5.0.12 #1312
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Lint | |
| on: | |
| pull_request: | |
| branches: | |
| - main | |
| push: | |
| branches: | |
| - main | |
| permissions: | |
| contents: read | |
| env: | |
| # actionlint and gitleaks are Go binaries with no first-party npm package, so neither Dependabot ecosystem | |
| # (npm, github-actions) tracks them. Bump these by hand; `npm run lint` uses whatever is on PATH locally. | |
| ACTIONLINT_VERSION: 1.7.12 | |
| GITLEAKS_VERSION: 8.30.1 | |
| jobs: | |
| format: | |
| name: Format | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| id: setup-node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| - name: Install Dependencies | |
| id: npm-ci | |
| run: npm ci --no-fund | |
| - name: Check Formatting | |
| id: format-check | |
| run: npm run format:check | |
| code: | |
| name: Code | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| id: setup-node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| - name: Install Dependencies | |
| id: npm-ci | |
| run: npm ci --no-fund | |
| - name: Lint Code | |
| id: lint-code | |
| run: npm run lint:code | |
| types: | |
| name: Types | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| id: setup-node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| - name: Install Dependencies | |
| id: npm-ci | |
| run: npm ci --no-fund | |
| - name: Lint Types | |
| id: lint-types | |
| run: npm run lint:types | |
| text: | |
| name: Text | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| id: setup-node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| - name: Install Dependencies | |
| id: npm-ci | |
| run: npm ci --no-fund | |
| - name: Lint Text | |
| id: lint-text | |
| run: npm run lint:text | |
| actions: | |
| name: Actions | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| id: setup-node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .node-version | |
| cache: npm | |
| - name: Install Dependencies | |
| id: npm-ci | |
| run: npm ci --no-fund | |
| # Installed as a binary rather than via a GitHub Action — actionlint publishes no action.yml at all. | |
| - name: Install actionlint | |
| id: install-actionlint | |
| run: | | |
| curl -sSfL "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" \ | |
| | sudo tar -xz -C /usr/local/bin actionlint | |
| actionlint --version | |
| # `external-linter.mjs` turns a missing binary into a hard failure when CI is set, so a broken | |
| # install step above can never look like a passing lint. | |
| - name: Lint Actions | |
| id: lint-actions | |
| run: npm run lint:actions | |
| secrets: | |
| name: Secrets | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| id: checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # Installed as a binary rather than via a GitHub Action. gitleaks-action is the paid product — the | |
| # CLI is not — and it gates on GITLEAKS_LICENSE *before* scanning; since secrets are never exposed | |
| # to workflows triggered from forked pull requests, that gate fails every external contribution with | |
| # an error the contributor cannot fix. The CLI needs no license, so forks scan exactly like branches. | |
| - name: Install gitleaks | |
| id: install-gitleaks | |
| run: | | |
| curl -sSfL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \ | |
| | sudo tar -xz -C /usr/local/bin gitleaks | |
| gitleaks version | |
| # Secret scanning is CI-only — it is not part of `npm run lint`, so contributors never need the | |
| # binary. `dir` scans the whole working tree on every run, unlike the action's default of scanning | |
| # only a pull request's own commit range, so a secret already sitting on main keeps failing CI until | |
| # it is removed. Exclusions live in .gitleaks.toml. | |
| - name: Scan for Secrets | |
| id: gitleaks | |
| run: gitleaks dir . --no-banner --redact | |
| # Aggregate gate preserving the single "Lint" check name the previous one-job workflow exposed, so any | |
| # branch-protection rule requiring "Lint" keeps working. Fails unless every lint job succeeded (a skipped | |
| # or cancelled dependency is a failure here, closing the skipped-check loophole). | |
| lint: | |
| name: Lint | |
| runs-on: ubuntu-latest | |
| needs: [format, code, types, text, actions, secrets] | |
| if: always() | |
| steps: | |
| - name: Verify All Lint Jobs Passed | |
| id: verify | |
| if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') || contains(needs.*.result, 'skipped') }} | |
| run: exit 1 |