chore(deps): bump actions/checkout from 4.2.2 to 7.0.1 #80
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security Checks | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| schedule: | |
| - cron: '0 9 * * 1' # Weekly Monday 9am UTC | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| shellcheck-strict: | |
| name: ShellCheck (error severity) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Run ShellCheck at error severity | |
| uses: ludeeus/action-shellcheck@00cae500b08a931fb5698e11e79bfbd38e612a38 # v2.0.0 | |
| with: | |
| scandir: '.' | |
| severity: error | |
| ignore_paths: node_modules | |
| secret-scan: | |
| name: Secret scanning | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Scan for hardcoded secrets | |
| run: | | |
| # Fail if real-looking API keys are found in tracked files | |
| if git ls-files | xargs grep -lniE \ | |
| "(sk-ant-api|ghp_[0-9A-Za-z]{36}|xoxb-[0-9A-Za-z-]+|AKIA[0-9A-Z]{16})" \ | |
| 2>/dev/null | grep -v ".git"; then | |
| echo "::error::Potential hardcoded secrets detected — see matches above" | |
| exit 1 | |
| fi | |
| echo "No hardcoded secrets detected" |