Skip to content

Align PMG integration: use PMG_PUBLIC_REPOS_TOKEN/PMG_TENANT_ID + add… #1

Align PMG integration: use PMG_PUBLIC_REPOS_TOKEN/PMG_TENANT_ID + add…

Align PMG integration: use PMG_PUBLIC_REPOS_TOKEN/PMG_TENANT_ID + add… #1

Workflow file for this run

name: PMG Proxy Test
on:
workflow_dispatch:
pull_request:
push:
jobs:
test-pmg-allows-clean-install:
name: PMG - Clean package should not be blocked
runs-on: ubuntu-latest
steps:
- name: Setup PMG proxy
uses: safedep/pmg@v1
with:
server-mode: true
api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }}
tenant-id: ${{ secrets.PMG_TENANT_ID }}
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install clean package (should succeed)
run: pip install requests
- name: Enforce PMG policy
if: always()
run: pmg proxy stop --fail-on-violation
test-pmg-blocks-malicious-package:
name: PMG - Malicious package should be blocked
runs-on: ubuntu-latest
steps:
- name: Setup PMG proxy
uses: safedep/pmg@v1
with:
server-mode: true
api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }}
tenant-id: ${{ secrets.PMG_TENANT_ID }}
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Install flagged test package (PMG should block this)
continue-on-error: true
run: npm install --no-cache --prefer-online safedep-test-pkg@0.1.3
- name: Enforce PMG policy (expect failure — violation recorded)
if: always()
run: pmg proxy stop --fail-on-violation