fastmcp/.github/workflows/run-static.yml
Bill Easton 6d6aee4168
Add gitleaks secret scanning to prek (#5355)
Add local and CI secret scanning with a pinned gitleaks installation and reviewed content-based exclusions.

Co-authored-by: Bill Easton <bill@pydantic.dev>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-04 20:39:41 -04:00

46 lines
1 KiB
YAML

name: Run static analysis
env:
PY_COLORS: 1
on:
push:
branches: ["main"]
# run on all pull requests because these checks are required and will block merges otherwise
pull_request:
workflow_dispatch:
# Only newer revisions of the same PR supersede a run. Main and manual runs
# use unique groups so they always complete.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
static_analysis:
timeout-minutes: 2
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Setup uv
uses: ./.github/actions/setup-uv
with:
resolution: locked
- name: Setup gitleaks
uses: ./.github/actions/setup-gitleaks
- name: Test workflows
run: node --test .github/scripts/test-*.mjs
- name: Run prek
uses: j178/prek-action@v3.0.0
env:
SKIP: no-commit-to-branch