ci(gitea): workflow — yamllint + secret scan on dev/release [#784]
ci / lint (push) Failing after 27s
ci / lint (push) Failing after 27s
Fleet CI standard; runner #784. Runs go green once the act_runner registers (token pending founder). https://projects.knownelement.com/issues/784
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# pfv-bms CI [#784 #778] — fleet standard per Discourse "CI/CD: Gitea Actions".
|
||||
# Runs on dev (pre-release gate) and release (final gate before live pull).
|
||||
name: ci
|
||||
on:
|
||||
push:
|
||||
branches: [dev, release]
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: node:20-bookworm
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: yamllint
|
||||
run: |
|
||||
pip install --quiet yamllint
|
||||
yamllint -c .yamllint .
|
||||
- name: secret scan
|
||||
run: |
|
||||
if grep -rInE "BEGIN (RSA |OPENSSH |EC |DSA )?PRIVATE KEY|aws_secret_access_key *=|AKIA[0-9A-Z]{16}" --exclude-dir=.git .; then
|
||||
echo "::error::secret material committed"; exit 1
|
||||
else
|
||||
echo "secret scan clean"
|
||||
fi
|
||||
@@ -0,0 +1,19 @@
|
||||
# HA-config-aware yamllint [#784]: keep the checks that catch real bugs
|
||||
# (duplicates, structure), relax the stylistic ones HA templates trip.
|
||||
extends: default
|
||||
ignore: |
|
||||
docs/
|
||||
rules:
|
||||
line-length: disable
|
||||
comments: disable
|
||||
comments-indentation: disable
|
||||
document-start: disable
|
||||
truthy: check-keys: false
|
||||
indentation:
|
||||
spaces: consistent
|
||||
indent-sequences: consistent
|
||||
key-duplicates: enable
|
||||
new-line-at-end-of-file: disable
|
||||
trailing-spaces: disable
|
||||
empty-lines:
|
||||
max-end: 2
|
||||
Reference in New Issue
Block a user