Files
SquidSec-SquidC5/.github/workflows/squidgate.yml
T
Mr. The Plague 3f8365632e security: GitHub-hosted CI + SHA-pinned actions for public SquidC5
Org Default runner group no longer allows public repos. Move CI/SquidGate
to ubuntu-latest/windows-latest and pin third-party actions to commit SHAs
(org sha_pinning_required). Document protected master + CI posture.
2026-08-04 11:41:41 -04:00

40 lines
1.1 KiB
YAML

name: SquidGate
on:
pull_request:
types: [opened, synchronize, reopened]
branches: [main, master]
permissions:
contents: read
pull-requests: write
checks: write
jobs:
squidgate:
# Same-repo PRs only — do not run fork PR code with LLM_API_KEY
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
env:
LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0
- name: SquidGate
if: env.LLM_API_KEY != ''
uses: SquidSec/SquidGate@5424e7343abbd7663bcc31920969f5a778ec8487 # v1.0.0-build.4
with:
llm-api-key: ${{ env.LLM_API_KEY }}
github-token: ${{ secrets.GITHUB_TOKEN }}
llm-provider: custom
llm-model: grok-build-0.1
llm-base-url: https://api.x.ai/v1
- name: SquidGate not configured
if: env.LLM_API_KEY == ''
run: |
echo "::notice title=SquidGate::Add repository secret LLM_API_KEY to enable the PR security gate (SquidSec/SquidGate)."