ci(automation): 补齐持续集成与开源安全检查 (#1)

This commit is contained in:
Evan
2026-09-06 10:02:01 +09:00
committed by GitHub
parent c45d8854e6
commit b64f2e9bdf
6 changed files with 167 additions and 0 deletions
+12
View File
@@ -0,0 +1,12 @@
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
groups:
actions:
patterns: ['*']
commit-message:
prefix: chore(deps)
open-pull-requests-limit: 5
+35
View File
@@ -0,0 +1,35 @@
name: CI
on:
push:
branches: [main]
pull_request:
merge_group:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: true
jobs:
native:
name: Native / ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
os: [ubuntu-24.04, macos-15, windows-2025]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Configure decoder regression tests
run: cmake -S tests -B build -DCMAKE_BUILD_TYPE=Release
- name: Configure dictionary builder
run: cmake -S command -B build-dictionary -DCMAKE_BUILD_TYPE=Release
- name: Build dictionary builder
run: cmake --build build-dictionary --config Release --parallel 4
- name: Build
run: cmake --build build --config Release --parallel 4
- name: Run regression tests
run: ctest --test-dir build -C Release --output-on-failure --no-tests=error --timeout 30
+37
View File
@@ -0,0 +1,37 @@
name: CodeQL
on:
push:
branches: [main]
pull_request:
schedule:
- cron: '15 3 * * 1'
workflow_dispatch:
permissions:
contents: read
concurrency:
group: codeql-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: true
jobs:
analyze:
name: CodeQL / ${{ matrix.language }}
runs-on: ubuntu-24.04
timeout-minutes: 30
permissions:
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
language: [actions, c-cpp, python]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4
with:
languages: ${{ matrix.language }}
# C/C++ source analysis complements, rather than replaces, native build CI.
build-mode: none
- uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4
with:
category: '/language:${{ matrix.language }}'
+44
View File
@@ -0,0 +1,44 @@
name: Repository quality
on:
push:
branches: [main]
pull_request:
merge_group:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: quality-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: true
jobs:
workflows:
name: Workflow validation
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
with:
go-version: '1.26'
cache: false
- name: Install actionlint
run: go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12
- name: Validate workflows and embedded shell scripts
env:
# Ignore style suggestions, but fail on shell correctness warnings and errors.
SHELLCHECK_OPTS: --severity=warning
run: actionlint -color
dependencies:
name: Dependency review
if: github.event_name == 'pull_request'
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4
with:
fail-on-severity: high