Skip to content

[StepSecurity] Apply security best practices #8

[StepSecurity] Apply security best practices

[StepSecurity] Apply security best practices #8

Workflow file for this run

name: Nix CI
on:
pull_request:
push:
branches:
- main
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
nix-ci:
name: Nix CI (${{ matrix.os }})
timeout-minutes: 90
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- name: Checkout
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22
- name: Enable Magic Nix Cache
uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14
with:
use-flakehub: false
use-gha-cache: true
- name: Run flake checks
run: nix flake check --print-build-logs
- name: Build default package
run: nix build .#default --print-build-logs
- name: Smoke-test CLI
run: |
nix run .#sce -- --help
nix run .#sce -- version