Repository navigation
feat(tsa): serve timestamps over HTTP behind a rate limit and clock gate #439
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: License Check | |
| # Fail if a 3rd-party dependency carries a license outside the allowlist. | |
| # Ecosystem-aware: each job early-exits if its manifest is absent. hashFiles() | |
| # is NOT valid in a job-level `if` (no workspace before checkout), so the | |
| # manifest check lives in a step. No SAST/vuln scanning (deliberately out of scope). | |
| on: | |
| pull_request: | |
| branches: [main] | |
| types: [opened, synchronize, reopened, ready_for_review] | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| # One run per PR per workflow: a new push cancels the older PR run. Pushes to | |
| # main are never cancelled, so every main commit keeps a result. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| npm: | |
| name: npm dependency licenses | |
| if: github.event.pull_request.draft != true | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Detect package.json | |
| id: manifest | |
| run: | | |
| if [ -f package.json ]; then echo "found=true" >> "$GITHUB_OUTPUT"; else echo "found=false (skipping)"; echo "found=false" >> "$GITHUB_OUTPUT"; fi | |
| - name: Setup Node | |
| if: steps.manifest.outputs.found == 'true' | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: lts/* | |
| - name: Install dependencies | |
| if: steps.manifest.outputs.found == 'true' | |
| run: npm install --ignore-scripts --no-audit --no-fund | |
| - name: Check dependency licenses | |
| if: steps.manifest.outputs.found == 'true' | |
| run: | | |
| npx --yes license-checker-rseidelsohn \ | |
| --production --excludePrivatePackages \ | |
| --onlyAllow "MIT;ISC;Apache-2.0;BSD-2-Clause;BSD-3-Clause;0BSD;CC0-1.0;Unlicense;BlueOak-1.0.0;Python-2.0;MPL-2.0;CC-BY-4.0" | |
| go: | |
| name: Go dependency licenses | |
| if: github.event.pull_request.draft != true | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Detect go.mod | |
| id: manifest | |
| run: | | |
| if [ -f go.mod ]; then echo "found=true" >> "$GITHUB_OUTPUT"; else echo "found=false (skipping)"; echo "found=false" >> "$GITHUB_OUTPUT"; fi | |
| - name: Setup Go | |
| if: steps.manifest.outputs.found == 'true' | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: 'stable' | |
| - name: Check dependency licenses | |
| if: steps.manifest.outputs.found == 'true' | |
| run: | | |
| go install github.com/google/go-licenses@latest | |
| "$(go env GOPATH)/bin/go-licenses" check ./... \ | |
| --allowed_licenses=MIT,ISC,Apache-2.0,BSD-2-Clause,BSD-3-Clause,0BSD,CC0-1.0,Unlicense,MPL-2.0,CC-BY-4.0 |