# Every push and pull request on the public repository: scripts/ci.sh, the gate a release passes — # types, tests, the compiled binary in a terminal, the licences, the shell scripts, and the # history for secrets. CI=1 makes a missing shellcheck or gitleaks a failure, not a skip. name: ci on: push: branches: [main, dev] pull_request: permissions: contents: read jobs: check: runs-on: ubuntu-latest timeout-minutes: 30 steps: - uses: actions/checkout@v4 with: fetch-depth: 0 # the secret scan reads the whole history persist-credentials: false - name: shellcheck, ripgrep run: sudo apt-get update -qq && sudo apt-get install -y -qq shellcheck ripgrep - name: gitleaks env: GITLEAKS: "8.30.1" run: | curl -fsSL -o gitleaks.tgz "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS}/gitleaks_${GITLEAKS}_linux_x64.tar.gz" curl -fsSL -o sums.txt "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS}/gitleaks_${GITLEAKS}_checksums.txt" echo "$(grep " gitleaks_${GITLEAKS}_linux_x64.tar.gz\$" sums.txt | cut -d' ' -f1) gitleaks.tgz" | sha256sum -c - tar -xzf gitleaks.tgz gitleaks && sudo install -m 0755 gitleaks /usr/local/bin/gitleaks && rm -f gitleaks gitleaks.tgz sums.txt - run: scripts/ci.sh env: CI: "1"