Repository navigation
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) … #142
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| name: Governance | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: [main, master] | |
| workflow_dispatch: | |
| permissions: | |
| actions: read | |
| contents: read | |
| jobs: | |
| governance: | |
| uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@a8f7249c3c5aef1ed6dfa16e637f13dfde815464 | |
| ruleset-regression: | |
| name: Ruleset repair regression | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Check shell syntax and offline ruleset behaviour | |
| shell: bash | |
| run: | | |
| bash -n scripts/branch-protection-apply.sh test/branch-protection-apply-test.sh | |
| bash test/branch-protection-apply-test.sh | |
| - name: Build the maintenance CLI package | |
| run: docker build --file Containerfile.maintenance --tag git-scripts-maintenance:test . | |
| - name: Exercise the package without network or a writable root filesystem | |
| run: | | |
| # The suite creates an executable gh test double in /tmp. | |
| docker run --rm --network none --read-only --cap-drop ALL \ | |
| --security-opt no-new-privileges \ | |
| --tmpfs /tmp:rw,exec,nosuid,nodev,uid=10001,gid=10001 \ | |
| --tmpfs /state:rw,nosuid,nodev,uid=10001,gid=10001 \ | |
| --entrypoint bash git-scripts-maintenance:test \ | |
| /opt/git-scripts/test/branch-protection-apply-test.sh |