ci: add build + vulnerability check for PRs (gates Renovate auto-merge)
CI / build (push) Failing after 40s
CI / build (push) Failing after 40s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Hs9HXPWVtqDukF9MbJKbpw
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
name: CI
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
DALAMUD_HOME: /tmp/dalamud
|
||||
PROJECT: CustomizePlus/CustomizePlus.csproj
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
- uses: actions/setup-dotnet@v4
|
||||
with:
|
||||
dotnet-version: 10.0.x
|
||||
- name: Download Dalamud
|
||||
run: |
|
||||
wget -q https://goatcorp.github.io/dalamud-distrib/latest.zip -O "$DALAMUD_HOME.zip"
|
||||
unzip -q "$DALAMUD_HOME.zip" -d "$DALAMUD_HOME"
|
||||
- name: Restore
|
||||
run: dotnet restore "$PROJECT"
|
||||
- name: Build
|
||||
run: dotnet build --configuration Release "$PROJECT" --no-restore
|
||||
- name: Fail on vulnerable packages
|
||||
run: |
|
||||
out=$(dotnet list "$PROJECT" package --vulnerable --include-transitive 2>&1)
|
||||
echo "$out"
|
||||
if echo "$out" | grep -qi 'has the following vulnerable'; then
|
||||
echo "::error::Vulnerable packages detected"; exit 1
|
||||
fi
|
||||
Reference in New Issue
Block a user