# Gitea Actions CI 模板(统一极简合规门禁) # 复制为 /.gitea/workflows/ci.yml 后即可用;无需调整。 # 说明:runner 容器无外网且无 pip(Gitea 实例限制),CI 只做本地可完成的合规检查; # 依赖安装与测试一律在本地运行(开发机上完成)。 name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ci-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: check: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Gitea 合规校验 run: | if git ls-tree -r HEAD | awk '$1==160000' | grep -q .; then echo "HEAD 含 gitlink"; exit 1; fi if git ls-files .DS_Store | grep -q .; then echo "跟踪 .DS_Store"; exit 1; fi if git grep -n -I -E 'sk-[A-Za-z0-9]{20,}|AKIA[0-9A-Z]{16}|ghp_[A-Za-z0-9]{36}|xox[baprs]-[A-Za-z0-9-]{10,}' HEAD | grep -q .; then echo "检出疑似凭证"; exit 1; fi echo "Gitea 合规校验通过"