Skip to content

Harden GitHub Action references #109

Harden GitHub Action references

Harden GitHub Action references #109

name: CI
on: [push, workflow_dispatch]
jobs:
build:
name: Swift on macos-latest
runs-on: macos-latest
steps:
- name: Extract Branch Name
run: echo "BRANCH=$(echo ${GITHUB_REF##*/})" >> $GITHUB_ENV
- name: Get swift version
run: swift --version
- uses: actions/checkout@v6
- name: Build
run: swift build
- name: Run tests
run: swift test
- name: Send Slack notification
if: failure() && env.BRANCH == 'main'
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
SLACK_TEXT: >-
${{ github.workflow }} failed for ${{ github.repository }} on ${{ github.ref_name }}:
${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
run: |
node -e "process.stdout.write(JSON.stringify({ text: process.env.SLACK_TEXT }))" |
curl --fail-with-body -X POST -H 'Content-type: application/json' --data-binary @- "$SLACK_WEBHOOK_URL"