diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index fc5fecb..ed33e18 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -1,7 +1,5 @@ -# Gitea Actions CI 模板(统一极简合规门禁) -# 复制为 /.gitea/workflows/ci.yml 后即可用;无需调整。 -# 说明:runner 容器无外网且无 pip(Gitea 实例限制),CI 只做本地可完成的合规检查; -# 依赖安装与测试一律在本地运行(开发机上完成)。 +# Gitea Actions CI(统一离线 lite 门禁) +# Runner 无外网且无 pip;这里只运行标准库测试和本地合规检查。 name: CI on: @@ -18,13 +16,18 @@ permissions: contents: read jobs: - check: + lite: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - name: Checkout + uses: actions/checkout@524e936cd9e579adf00e308bfdf971aebc7de09e + with: + persist-credentials: false - name: Gitea 合规校验 run: | if git ls-tree -r HEAD | awk '$1==160000' | grep -q .; then echo "HEAD 含 gitlink"; exit 1; fi if git ls-files .DS_Store | grep -q .; then echo "跟踪 .DS_Store"; exit 1; fi if git grep -n -I -E 'sk-[A-Za-z0-9]{20,}|AKIA[0-9A-Z]{16}|ghp_[A-Za-z0-9]{36}|xox[baprs]-[A-Za-z0-9-]{10,}' HEAD | grep -q .; then echo "检出疑似凭证"; exit 1; fi echo "Gitea 合规校验通过" + - name: 规则契约测试 + run: python3 -m unittest discover -s tests -v