Skip to content

πŸ”§ CodeRabbit CI Fix: Fix failing Hypatia GitHub Check CI job #577

πŸ”§ CodeRabbit CI Fix: Fix failing Hypatia GitHub Check CI job

πŸ”§ CodeRabbit CI Fix: Fix failing Hypatia GitHub Check CI job #577

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# self-test β€” run this repo's own test suite.
#
# WHY: `tests/test_check_trusted_base.sh` has existed for some time and was
# wired into NO workflow. A test that never executes is indistinguishable from
# a test that passes β€” the same shape as the `continue-on-error` gitleaks step
# and the `./src`-only rust-secrets grep. This workflow closes that gap by
# running every `tests/*.sh`, so adding a test is enough to have it enforced.
#
# The suite is deliberately FAIL-CLOSED: an empty tests/ directory, a
# non-executable test, or a missing interpreter fails the job rather than
# reporting a vacuous pass.
name: Self Test
on:
pull_request:
push:
branches: [main]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
tests:
name: Repo self-tests
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# PyYAML is required by the secret-scanner canary. The scorecard
# grounding tests execute the same checks as registry-verify, including
# checks that require ripgrep and xmllint.
- name: Install test dependencies
run: |
sudo apt-get update -qq
sudo apt-get install -y --no-install-recommends ripgrep libxml2-utils
python3 -m pip install --user --quiet pyyaml
- name: Run tests/*.sh and scripts/tests/*.sh
run: bash scripts/run-shell-test-suite.sh