From 6539b696cc9078c82e031db045a93d9c2d63a516 Mon Sep 17 00:00:00 2001 From: lozy360 Date: Sun, 6 Sep 2026 22:55:06 +0200 Subject: [PATCH] ci: restore + vulnerability scan only (drop flaky Dalamud build) --- .gitea/workflows/ci.yml | 18 ++++++------------ 1 file changed, 6 insertions(+), 12 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 462b2df..0247c4e 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -10,12 +10,12 @@ concurrency: group: ci-${{ github.ref }} cancel-in-progress: true +# Gate for Renovate auto-merge. A full `dotnet build` needs the Dalamud +# assemblies (staging channel) and is too flaky for a merge gate, so this +# verifies the NuGet graph resolves and introduces no known-vulnerable package. jobs: - build: + deps: runs-on: ubuntu-latest - env: - DALAMUD_HOME: /tmp/dalamud - PROJECT: GlamourBrowser/GlamourBrowser.csproj steps: - uses: actions/checkout@v4 with: @@ -23,17 +23,11 @@ jobs: - uses: actions/setup-dotnet@v4 with: dotnet-version: 10.0.x - - name: Download Dalamud - run: | - wget -q https://goatcorp.github.io/dalamud-distrib/stg/latest.zip -O "$DALAMUD_HOME.zip" - unzip -q "$DALAMUD_HOME.zip" -d "$DALAMUD_HOME" - name: Restore - run: dotnet restore "$PROJECT" - - name: Build - run: dotnet build --configuration Release "$PROJECT" --no-restore + run: dotnet restore - name: Fail on vulnerable packages run: | - out=$(dotnet list "$PROJECT" package --vulnerable --include-transitive 2>&1) + out=$(dotnet list package --vulnerable --include-transitive 2>&1) echo "$out" if echo "$out" | grep -qi 'has the following vulnerable'; then echo "::error::Vulnerable packages detected"; exit 1