Repository navigation
CI CD
Domini Montessori edited this page Aug 20, 2026
·
1 revision
Workflow inventory for dominicusin.github.io. All checks must pass on main.
-
🧪 Build, validate, test, link-check (
quality.yml) — the only required status check. Lint + Hugo build + Jest + Playwright + link check.
| Workflow | Purpose | Blocking? |
|---|---|---|
security.yml |
npm audit + Trivy + Semgrep | no |
security-scan.yml |
CodeQL + Gitleaks | no |
dependency-review.yml |
block PRs with new vulns | PR-only |
sbom.yml |
generate SBOM + attest | no |
scorecard.yml |
OpenSSF Scorecard | no (continue-on-error) |
license-check.yml |
license allowlist | no |
-
stale.yml— auto-close stale issues/PRs -
lock-threads.yml— lock old threads -
labeler.yml+labeler.ymlconfig — auto-label by path -
pr-title-check.yml— Conventional Commits reminder -
size-label.yml— PR size label
-
hugo.yml— build + deploy to GitHub Pages (artifact attestation viaactions/attest@v4.2.2). -
deploy-dao.yml— DAO contract tests always run; deploy job skips whenDEPLOY_PRIVATE_KEY/SEPOLIA_RPC_URLsecrets are absent. -
fortify.yml— Fortify AST scan, skips without credentials.
- Vercel, Snyk — third-party GitHub Apps failing on rate/test limits. Not fixable from this repo; disable in repo Settings → Integrations if unwanted.
-
CircleCI — fixed via
.circleci/config.yml.