chore: sync OKF bundle from opendpp-node@f96a1f3 #59
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| # Validates that the published bundle is OKF-conformant (frontmatter + no broken internal links), | |
| # using the zero-dependency validate.mjs — so the public repo is independently checkable. | |
| # | |
| # Actions are pinned to full commit SHAs (OpenSSF guidance); the github-actions Dependabot ecosystem | |
| # (.github/dependabot.yml) keeps the pins fresh. Matches the OpenDPP/opendpp-node and | |
| # OpenDPP/opendpp-interop posture. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| name: OKF conformance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 | |
| - run: node validate.mjs | |
| secret-scan: | |
| name: Secret scan (gitleaks) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Run gitleaks | |
| env: | |
| # Pinned manual download — NOT gitleaks-action, which requires a GITLEAKS_LICENSE key for | |
| # organization-owned repos (this repo is under the OpenDPP org). Mirrors the secret-scan job in | |
| # OpenDPP/opendpp-interop. Pinned so the scan never depends on an unauthenticated, rate-limited | |
| # `releases/latest` lookup at runtime. Bump deliberately. | |
| GITLEAKS_VERSION: "8.30.1" | |
| run: | | |
| set -euo pipefail | |
| url="https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" | |
| for attempt in 1 2 3; do | |
| if curl -fsSL --retry 3 --retry-all-errors "$url" | tar -xz gitleaks; then | |
| break | |
| fi | |
| echo "gitleaks download failed (attempt $attempt) — retrying" >&2 | |
| sleep $((attempt * 5)) | |
| done | |
| test -x ./gitleaks | |
| ./gitleaks detect --source . --redact --no-banner |