Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 45 additions & 0 deletions .github/workflows/actionlint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
name: actionlint

on:
push:
branches: [main]
paths:
- '.github/workflows/**'
- '.github/actionlint*'
pull_request:
branches: [main]
paths:
- '.github/workflows/**'
- '.github/actionlint*'

concurrency:
group: actionlint-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
actionlint:
name: actionlint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
Comment thread
coderabbitai[bot] marked this conversation as resolved.
with:
persist-credentials: false

- name: Download actionlint
id: actionlint
run: |
set -euo pipefail
VERSION=1.7.7
TARBALL="actionlint_${VERSION}_linux_amd64.tar.gz"
curl -fsSL -o "/tmp/${TARBALL}" "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/${TARBALL}"
curl -fsSL -o /tmp/checksums.txt "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/actionlint_${VERSION}_checksums.txt"
cd /tmp && grep "${TARBALL}" checksums.txt | sha256sum -c -
tar -xzf "/tmp/${TARBALL}" -C /tmp actionlint
echo "executable=/tmp/actionlint" >> "$GITHUB_OUTPUT"

- name: Run actionlint
run: |
"${{ steps.actionlint.outputs.executable }}" -color
61 changes: 61 additions & 0 deletions .github/workflows/gitleaks.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
name: Gitleaks

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# 毎週月曜 05:00 JST (= 日曜 20:00 UTC) に履歴全体を再スキャン
- cron: '0 20 * * 0'
workflow_dispatch:

concurrency:
group: gitleaks-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
security-events: write

jobs:
gitleaks:
name: Scan for leaked secrets
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
# 履歴全体をスキャンするためフルクローン
fetch-depth: 0
persist-credentials: false

- name: Install gitleaks
run: |
set -euo pipefail
GITLEAKS_VERSION=8.21.2
TARBALL="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
CHECKSUMS="gitleaks_${GITLEAKS_VERSION}_checksums.txt"
curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${TARBALL}"
curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${CHECKSUMS}"
grep -F " ${TARBALL}" "${CHECKSUMS}" | sha256sum -c -
tar -xzf "${TARBALL}" gitleaks
sudo mv gitleaks /usr/local/bin/gitleaks
Comment thread
coderabbitai[bot] marked this conversation as resolved.
gitleaks version

- name: Run gitleaks
run: |
gitleaks detect \
--source . \
--redact \
--verbose \
--no-banner \
--exit-code 1 \
--report-format sarif \
--report-path gitleaks.sarif

- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3
with:
sarif_file: gitleaks.sarif
category: gitleaks
40 changes: 40 additions & 0 deletions .github/workflows/markdownlint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: markdownlint

on:
push:
branches: [main]
paths:
- '**/*.md'
- '.markdownlint-cli2.jsonc'
- '.github/workflows/markdownlint.yml'
pull_request:
branches: [main]
paths:
- '**/*.md'
- '.markdownlint-cli2.jsonc'
- '.github/workflows/markdownlint.yml'

concurrency:
group: markdownlint-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
markdownlint:
name: markdownlint-cli2
runs-on: ubuntu-latest
# 既存ドキュメントの MD040/MD031 違反を片付けるまでは赤検知にしない。
# 整備完了後に continue-on-error を外して赤検知に切り替える。
continue-on-error: true
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
persist-credentials: false

- name: Run markdownlint-cli2
uses: DavidAnson/markdownlint-cli2-action@992badcdf24e3b8eb7e87ff9287fe931bcb00c6e # v20
with:
config: '.markdownlint-cli2.jsonc'
globs: '**/*.md'
27 changes: 27 additions & 0 deletions .markdownlint-cli2.jsonc
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{
// markdownlint-cli2 設定
// https://github.com/DavidAnson/markdownlint-cli2
"config": {
"default": true,
// 行長制限: コード/表/長文を伴うドキュメントが多いので無効化
"MD013": false,
// インライン HTML: README や PR テンプレで <!-- --> やテーブル装飾を使うので許可
"MD033": false,
// 単一の H1 を強制: 既存ドキュメントが満たさないものがあるため無効化
"MD025": false,
// 重複ヘッダ: docs で「概要」が複数出るので緩める
"MD024": { "siblings_only": true },
// 最初の行が H1 でなくてもよい (PR テンプレなど)
"MD041": false,
// 強調を見出しに使ってよい
"MD036": false,
// bare URL を許可 (GitHub flavored Markdown で自動リンク化される)
"MD034": false,
// テーブルパイプスタイル: 重要度が低いため無効化
"MD055": false,
// blockquote 内の空行: 引用節を見やすくするため許可
"MD028": false,
},
"globs": ["**/*.md"],
"ignores": ["**/node_modules/**", ".claude/**", "**/dist/**", "**/build/**"],
}
Loading