chore: pin checkout, stop persisting credentials and cover main.py fully #762
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Commit Check | |
| on: | |
| pull_request: | |
| branches: 'main' | |
| types: [opened, synchronize, reopened, edited] | |
| workflow_dispatch: | |
| jobs: | |
| commit-check: | |
| strategy: | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 # Required for merge-base checks | |
| # Nothing after checkout needs authenticated git. | |
| persist-credentials: false | |
| - uses: ./ # self test | |
| with: | |
| message: true | |
| branch: true | |
| author-name: true | |
| author-email: true | |
| # Report from the ubuntu job only. Every leg checks the same commits | |
| # against the same rules, so the other two produce a byte-identical | |
| # report — three copies of it on the run page, and the matrix is here | |
| # to prove the action runs on each OS, not to say the same thing | |
| # three times. | |
| job-summary: ${{ matrix.os == 'ubuntu-latest' }} | |
| pr-comments: ${{ github.event_name == 'pull_request' && matrix.os == 'ubuntu-latest' }} | |
| pr-title: true |