Skip to content

chore: remove the appliance code that moved to cryptos-appliance #430

chore: remove the appliance code that moved to cryptos-appliance

chore: remove the appliance code that moved to cryptos-appliance #430

name: License Check
# Fail if a 3rd-party dependency carries a license outside the allowlist.
# Ecosystem-aware: each job early-exits if its manifest is absent. hashFiles()
# is NOT valid in a job-level `if` (no workspace before checkout), so the
# manifest check lives in a step. No SAST/vuln scanning (deliberately out of scope).
on:
pull_request:
branches: [main]
types: [opened, synchronize, reopened, ready_for_review]
push:
branches: [main]
permissions:
contents: read
# One run per PR per workflow: a new push cancels the older PR run. Pushes to
# main are never cancelled, so every main commit keeps a result.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
npm:
name: npm dependency licenses
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Detect package.json
id: manifest
run: |
if [ -f package.json ]; then echo "found=true" >> "$GITHUB_OUTPUT"; else echo "found=false (skipping)"; echo "found=false" >> "$GITHUB_OUTPUT"; fi
- name: Setup Node
if: steps.manifest.outputs.found == 'true'
uses: actions/setup-node@v4
with:
node-version: lts/*
- name: Install dependencies
if: steps.manifest.outputs.found == 'true'
run: npm install --ignore-scripts --no-audit --no-fund
- name: Check dependency licenses
if: steps.manifest.outputs.found == 'true'
run: |
npx --yes license-checker-rseidelsohn \
--production --excludePrivatePackages \
--onlyAllow "MIT;ISC;Apache-2.0;BSD-2-Clause;BSD-3-Clause;0BSD;CC0-1.0;Unlicense;BlueOak-1.0.0;Python-2.0;MPL-2.0;CC-BY-4.0"
go:
name: Go dependency licenses
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Detect go.mod
id: manifest
run: |
if [ -f go.mod ]; then echo "found=true" >> "$GITHUB_OUTPUT"; else echo "found=false (skipping)"; echo "found=false" >> "$GITHUB_OUTPUT"; fi
- name: Setup Go
if: steps.manifest.outputs.found == 'true'
uses: actions/setup-go@v5
with:
go-version: 'stable'
- name: Check dependency licenses
if: steps.manifest.outputs.found == 'true'
run: |
go install github.com/google/go-licenses@latest
"$(go env GOPATH)/bin/go-licenses" check ./... \
--allowed_licenses=MIT,ISC,Apache-2.0,BSD-2-Clause,BSD-3-Clause,0BSD,CC0-1.0,Unlicense,MPL-2.0,CC-BY-4.0