diff --git a/.github/workflows/test-action.yaml b/.github/workflows/test-action.yaml index 4481e0b..78bc09a 100644 --- a/.github/workflows/test-action.yaml +++ b/.github/workflows/test-action.yaml @@ -7,15 +7,21 @@ concurrency: group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} +permissions: {} + jobs: test_ct_action: runs-on: ubuntu-latest + permissions: + contents: read # Clone the repository name: Install chart-testing and test presence in path steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install chart-testing - uses: ./ + uses: $/./ - name: Check install! run: | ct version @@ -39,12 +45,16 @@ jobs: test_ct_action_custom: runs-on: ubuntu-latest + permissions: + contents: read # Clone the repository name: Install Custom chart-testing and test presence in path steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Install chart-testing - uses: ./ + uses: $/./ with: version: 'v3.8.0' yamllint_version: '1.27.1' @@ -72,12 +82,15 @@ jobs: test_ct_action_with_helm: runs-on: ubuntu-latest + permissions: + contents: read # Clone the repository and diff against the target branch name: run action to test a helm chart steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 + persist-credentials: false - name: Set up Helm uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 @@ -90,7 +103,7 @@ jobs: check-latest: true - name: Install chart-testing - uses: ./ + uses: $/./ - run: | sed -i "s/version: .*/version: 2.0.0/" testdata/simple-deployment/Chart.yaml @@ -98,20 +111,26 @@ jobs: - name: Run chart-testing (list-changed) id: list-changed + env: + BRANCH_NAME: ${{ github.event.repository.default_branch }} run: | - changed=$(ct list-changed --chart-dirs=testdata --target-branch ${{ github.event.repository.default_branch }}) + changed=$(ct list-changed --chart-dirs=testdata --target-branch ${BRANCH_NAME}) if [[ -n "$changed" ]]; then echo "changed=true" >> "$GITHUB_OUTPUT" fi - name: Run chart-testing (lint) if: steps.list-changed.outputs.changed == 'true' - run: ct lint --chart-dirs=testdata --target-branch ${{ github.event.repository.default_branch }} + env: + BRANCH_NAME: ${{ github.event.repository.default_branch }} + run: ct lint --chart-dirs=testdata --target-branch ${BRANCH_NAME} - name: Create kind cluster if: steps.list-changed.outputs.changed == 'true' - uses: helm/kind-action@v1.15.0 + uses: helm/kind-action@06c1ae10762d3b9c1644e7fe69596ae519e015a2 # v1.15.0 - name: Run chart-testing (install) if: steps.list-changed.outputs.changed == 'true' - run: ct install --chart-dirs=testdata --target-branch ${{ github.event.repository.default_branch }} + env: + BRANCH_NAME: ${{ github.event.repository.default_branch }} + run: ct install --chart-dirs=testdata --target-branch ${BRANCH_NAME}