Repository navigation
Align PMG integration: use PMG_PUBLIC_REPOS_TOKEN/PMG_TENANT_ID + add… #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: PMG Proxy Test | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| push: | |
| jobs: | |
| test-pmg-allows-clean-install: | |
| name: PMG - Clean package should not be blocked | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Setup PMG proxy | |
| uses: safedep/pmg@v1 | |
| with: | |
| server-mode: true | |
| api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }} | |
| tenant-id: ${{ secrets.PMG_TENANT_ID }} | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install clean package (should succeed) | |
| run: pip install requests | |
| - name: Enforce PMG policy | |
| if: always() | |
| run: pmg proxy stop --fail-on-violation | |
| test-pmg-blocks-malicious-package: | |
| name: PMG - Malicious package should be blocked | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Setup PMG proxy | |
| uses: safedep/pmg@v1 | |
| with: | |
| server-mode: true | |
| api-key: ${{ secrets.PMG_PUBLIC_REPOS_TOKEN }} | |
| tenant-id: ${{ secrets.PMG_TENANT_ID }} | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| - name: Install flagged test package (PMG should block this) | |
| continue-on-error: true | |
| run: npm install --no-cache --prefer-online safedep-test-pkg@0.1.3 | |
| - name: Enforce PMG policy (expect failure — violation recorded) | |
| if: always() | |
| run: pmg proxy stop --fail-on-violation |