Skip to content

chore(ci): sync secret gate to runpod/secret_detector@41611d2f1f56 #4

chore(ci): sync secret gate to runpod/secret_detector@41611d2f1f56

chore(ci): sync secret gate to runpod/secret_detector@41611d2f1f56 #4

name: Gate regression tests
# Hermetic: no network, no tokens, no betterleaks binary; scanner output comes from recorded fixtures.
# Jobs declare their own permissions; this empty default covers any that do not.
permissions: {}
on:
push:
paths:
- '.github/security/**'
- '.github/workflows/security_gate_tests.yml'
pull_request:
paths:
- '.github/security/**'
- '.github/workflows/security_gate_tests.yml'
workflow_dispatch:
jobs:
test:
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions/setup-python@v7
with:
python-version: "3.12"
- name: Install pytest
run: "pip install --disable-pip-version-check --only-binary :all: pytest==8.4.2 pyyaml==6.0.3"
- name: Run the gate regression suite
working-directory: .github/security
run: pytest . -v