docs(readme): the branding capability, corrected counts, and the seve… #7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| verify: | |
| name: Typecheck and test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # No version pin here. pnpm/action-setup reads packageManager from | |
| # package.json, and giving it both is a hard error. | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - name: Install | |
| run: pnpm install --no-frozen-lockfile | |
| - name: Typecheck | |
| run: pnpm -r typecheck | |
| - name: Test | |
| run: pnpm -r test | |
| # The disclosure boundary is the security property of the whole system. | |
| # If this fails, some role can see a field it must not, and nothing else | |
| # about the build matters. | |
| - name: Verify disclosure boundary | |
| run: pnpm --filter @dpa/govern test |