-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathaction.yml
More file actions
54 lines (50 loc) · 1.83 KB
/
Copy pathaction.yml
File metadata and controls
54 lines (50 loc) · 1.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
name: SchemaShield Offline Preflight
description: Generate evidence-backed schema-risk artifacts and optionally block risky changes.
author: RELAUNCH DEPT.
branding:
icon: shield
color: blue
inputs:
fixture:
description: Path to an ESM fixture that exports schemaChange, catalogSnapshot, and policy.
required: true
output-directory:
description: Workspace-relative directory for the seven generated review artifacts.
required: false
default: schema-shield-artifacts
fail-on:
description: "Failure threshold: never, breaking, medium, high, or critical."
required: false
default: critical
force:
description: Replace SchemaShield artifacts already present in the output directory.
required: false
default: "false"
outputs:
risk:
description: LOW, MEDIUM, HIGH, or CRITICAL.
value: ${{ steps.preflight.outputs.risk }}
breaking:
description: Whether the fixture describes a breaking change.
value: ${{ steps.preflight.outputs.breaking }}
block-merge:
description: Whether the current policy marks the change as merge-blocking.
value: ${{ steps.preflight.outputs.block-merge }}
run-id:
description: Deterministic SHA-256 identifier for the analyzed inputs.
value: ${{ steps.preflight.outputs.run-id }}
artifact-directory:
description: Absolute path to the generated artifact directory.
value: ${{ steps.preflight.outputs.artifact-directory }}
runs:
using: composite
steps:
- id: preflight
shell: bash
env:
SCHEMA_SHIELD_ACTION_PATH: ${{ github.action_path }}
SCHEMA_SHIELD_FAIL_ON: ${{ inputs.fail-on }}
SCHEMA_SHIELD_FIXTURE: ${{ inputs.fixture }}
SCHEMA_SHIELD_FORCE: ${{ inputs.force }}
SCHEMA_SHIELD_OUTPUT_DIRECTORY: ${{ inputs.output-directory }}
run: node "$SCHEMA_SHIELD_ACTION_PATH/action/run.mjs"