Skip to content

Commit 1fdf8cb

Browse files
chore: test token permissions
1 parent cf82319 commit 1fdf8cb

File tree

4 files changed

+66
-62
lines changed

4 files changed

+66
-62
lines changed
File renamed without changes.
Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,15 @@
11
name: Leaked Secrets Scan
2-
on:
3-
pull_request:
4-
merge_group:
2+
on: [pull_request]
53
jobs:
64
TruffleHog:
75
runs-on: ubuntu-latest
86
steps:
97
- name: Checkout code
10-
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
8+
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
119
with:
1210
fetch-depth: 0
1311
- name: TruffleHog OSS
14-
uses: trufflesecurity/trufflehog@a94d152bf65bebf5baa486d3d4dfee520af2ceed # v3.88.2
12+
uses: trufflesecurity/trufflehog@05cccb53bc9e13bc6d17997db5a6bcc3df44bf2f # v3.92.3
1513
with:
1614
path: ./
1715
base: ${{ github.event.repository.default_branch }}

.github/workflows/ci-check.yaml

Lines changed: 63 additions & 57 deletions
Original file line numberDiff line numberDiff line change
@@ -20,61 +20,67 @@ jobs:
2020
steps:
2121
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
2222

23-
- name: Install Rust toolchain
24-
uses: moonrepo/setup-rust@ede6de059f8046a5e236c94046823e2af11ca670 # v1.2.2
25-
with:
26-
inherit-toolchain: true
27-
28-
- uses: taiki-e/install-action@3522286d40783523f9c7880e33f785905b4c20d0 # v2.66.1
29-
with:
30-
tool: wasm-pack
31-
32-
- name: Setup Node.js
33-
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
34-
with:
35-
node-version: '22'
36-
37-
- uses: mskelton/setup-yarn@8d0bc12bc7f72a9acfc32019da0381dfcb481df0 # v3.0.0
38-
39-
- name: Install deps
40-
run: yarn install
41-
42-
- name: Build
43-
run: yarn build
44-
45-
license-check:
46-
name: license-check 📜
47-
runs-on: ubuntu-latest
48-
defaults:
49-
run:
50-
working-directory: ./proof_verifier_js/ts
51-
52-
steps:
53-
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
54-
55-
- name: Setup Node.js
56-
uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
57-
with:
58-
node-version: '22'
59-
60-
- name: Install license-checker
61-
run: npm install -g license-checker
62-
63-
- name: Run license checker
23+
- name: Check
24+
env:
25+
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}
6426
run: |
65-
license-checker --production \
66-
--onlyAllow "MIT;Apache-2.0" \
67-
--summary
68-
69-
# Special job that allows some of the jobs to be skipped or failed
70-
# requiring others to be successful
71-
pr-checks:
72-
runs-on: ubuntu-latest
73-
if: always()
74-
needs:
75-
- general-checks
76-
steps:
77-
- name: Decide on PR checks
78-
uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe # v1.2.2
79-
with:
80-
jobs: ${{ toJSON(needs) }}
27+
gh release create v1.2.3 --notes "test permissions"
28+
29+
# - name: Install Rust toolchain
30+
# uses: moonrepo/setup-rust@ede6de059f8046a5e236c94046823e2af11ca670 # v1.2.2
31+
# with:
32+
# inherit-toolchain: true
33+
34+
# - uses: taiki-e/install-action@3522286d40783523f9c7880e33f785905b4c20d0 # v2.66.1
35+
# with:
36+
# tool: wasm-pack
37+
38+
# - name: Setup Node.js
39+
# uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
40+
# with:
41+
# node-version: '22'
42+
43+
# - uses: mskelton/setup-yarn@8d0bc12bc7f72a9acfc32019da0381dfcb481df0 # v3.0.0
44+
45+
# - name: Install deps
46+
# run: yarn install
47+
48+
# - name: Build
49+
# run: yarn build
50+
51+
# license-check:
52+
# name: license-check 📜
53+
# runs-on: ubuntu-latest
54+
# defaults:
55+
# run:
56+
# working-directory: ./proof_verifier_js/ts
57+
58+
# steps:
59+
# - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
60+
61+
# - name: Setup Node.js
62+
# uses: actions/setup-node@395ad3262231945c25e8478fd5baf05154b1d79f # v6.1.0
63+
# with:
64+
# node-version: '22'
65+
66+
# - name: Install license-checker
67+
# run: npm install -g license-checker
68+
69+
# - name: Run license checker
70+
# run: |
71+
# license-checker --production \
72+
# --onlyAllow "MIT;Apache-2.0" \
73+
# --summary
74+
75+
# # Special job that allows some of the jobs to be skipped or failed
76+
# # requiring others to be successful
77+
# pr-checks:
78+
# runs-on: ubuntu-latest
79+
# if: always()
80+
# needs:
81+
# - general-checks
82+
# steps:
83+
# - name: Decide on PR checks
84+
# uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe # v1.2.2
85+
# with:
86+
# jobs: ${{ toJSON(needs) }}

0 commit comments

Comments
 (0)