ci(gitea): workflow — yamllint + secret scan on dev/release [#784]
ci / lint (push) Failing after 27s
ci / lint (push) Failing after 27s
Fleet CI standard; runner #784. Runs go green once the act_runner registers (token pending founder). https://projects.knownelement.com/issues/784
This commit is contained in:
@@ -0,0 +1,24 @@
|
|||||||
|
# pfv-bms CI [#784 #778] — fleet standard per Discourse "CI/CD: Gitea Actions".
|
||||||
|
# Runs on dev (pre-release gate) and release (final gate before live pull).
|
||||||
|
name: ci
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [dev, release]
|
||||||
|
jobs:
|
||||||
|
lint:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
container:
|
||||||
|
image: node:20-bookworm
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- name: yamllint
|
||||||
|
run: |
|
||||||
|
pip install --quiet yamllint
|
||||||
|
yamllint -c .yamllint .
|
||||||
|
- name: secret scan
|
||||||
|
run: |
|
||||||
|
if grep -rInE "BEGIN (RSA |OPENSSH |EC |DSA )?PRIVATE KEY|aws_secret_access_key *=|AKIA[0-9A-Z]{16}" --exclude-dir=.git .; then
|
||||||
|
echo "::error::secret material committed"; exit 1
|
||||||
|
else
|
||||||
|
echo "secret scan clean"
|
||||||
|
fi
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
# HA-config-aware yamllint [#784]: keep the checks that catch real bugs
|
||||||
|
# (duplicates, structure), relax the stylistic ones HA templates trip.
|
||||||
|
extends: default
|
||||||
|
ignore: |
|
||||||
|
docs/
|
||||||
|
rules:
|
||||||
|
line-length: disable
|
||||||
|
comments: disable
|
||||||
|
comments-indentation: disable
|
||||||
|
document-start: disable
|
||||||
|
truthy: check-keys: false
|
||||||
|
indentation:
|
||||||
|
spaces: consistent
|
||||||
|
indent-sequences: consistent
|
||||||
|
key-duplicates: enable
|
||||||
|
new-line-at-end-of-file: disable
|
||||||
|
trailing-spaces: disable
|
||||||
|
empty-lines:
|
||||||
|
max-end: 2
|
||||||
Reference in New Issue
Block a user