* [StepSecurity] Apply security best practices * Keep needed check in precommit --------- Signed-off-by: StepSecurity Bot <bot@stepsecurity.io> Signed-off-by: Sanket Sudake <sanketsudake@gmail.com> Co-authored-by: StepSecurity Bot <bot@stepsecurity.io>
44 lines
1.1 KiB
YAML
44 lines
1.1 KiB
YAML
name: Lint dashboards
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- 'charts/fission-all/dashboards/**.json'
|
|
pull_request:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- 'charts/fission-all/dashboards/**.json'
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
lint-dashboards:
|
|
runs-on: ubuntu-latest
|
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@0080882f6c36860b6ba35c610c98ce87d4e2f26f # v2.10.2
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Check out code
|
|
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 # v4.2.0
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
|
|
with:
|
|
go-version-file: "go.mod"
|
|
|
|
- name: Install dashboard linter
|
|
run: |
|
|
go get github.com/grafana/dashboard-linter
|
|
go install github.com/grafana/dashboard-linter
|
|
|
|
- name: Run dashboard linter
|
|
run: ./hack/lint-dashboards.sh
|