Skip to content

fix(validate): stop legacy A2ML identity forms satisfying a .deed #10

fix(validate): stop legacy A2ML identity forms satisfying a .deed

fix(validate): stop legacy A2ML identity forms satisfying a .deed #10

# SPDX-License-Identifier: MPL-2.0
# Behavioural test for .deed support in actions/validate/validate-a2ml.sh.
#
# Deliberately bash-only: it must not depend on the Idris2 toolchain, so that
# it reports on the shell validator independently of the CLI build.
name: Deed Conformance
# This workflow only reads the tree and runs a bash test script: it does not
# post statuses, comment, or write to the repository. read-all grants every
# read scope there is (actions, packages, deployments, security events...);
# contents: read is the only one actually exercised.
permissions:
contents: read
on:
push:
paths:
- 'actions/validate/**'
- '.github/workflows/deed-conformance.yml'
pull_request:
paths:
- 'actions/validate/**'
- '.github/workflows/deed-conformance.yml'
workflow_dispatch:
jobs:
deed-conformance:
name: Deed fixtures — all four ruled heads
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
with:
# No step here pushes or otherwise uses the token, and this workflow
# runs on pull_request against repository-controlled code, so leaving
# the credential in .git/config is exposure with no upside (CWE-522).
persist-credentials: false
- name: Run deed conformance tests
run: bash actions/validate/conformance/run-deed-tests.sh