Skip to main content
EVOKORE// WORKFLOWS / reusable-security.yml
EVOKORE-MCPworkflow · 21 lines

.github/workflows/reusable-security.yml

CI / automation

View on GitHub →
name: Reusable Security
on:
  workflow_call:
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: '20'
          cache: 'npm'
      - run: npm ci
      - name: Audit dependencies
        run: npm audit --audit-level=high || true
      - name: Check for secrets
        run: |
          if grep -rE "(password|secret|api_key)\s*=\s*['\"][^'\"]{8,}" src/ --include="*.ts" 2>/dev/null; then
            echo "Potential secrets found"; exit 1
          fi