Repository navigation
docs: overhaul demo gif, dashboard visual, and README marketing matrix #16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [ main, master ] | |
| pull_request: | |
| branches: [ main, master ] | |
| workflow_dispatch: | |
| jobs: | |
| test: | |
| name: Build & Test (${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ macos-latest, ubuntu-latest ] | |
| env: | |
| MACHAR_ALLOW_NON_DARWIN: 1 | |
| steps: | |
| - name: Checkout Code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Setup Linux Dependencies | |
| if: runner.os == 'Linux' | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y zsh bash shellcheck python3 | |
| - name: Setup macOS Dependencies | |
| if: runner.os == 'macOS' | |
| run: | | |
| if ! command -v shellcheck &>/dev/null; then | |
| brew install shellcheck | |
| fi | |
| - name: ShellCheck Bash Integration | |
| run: | | |
| echo "Running ShellCheck on the Bash completion integration..." | |
| shellcheck --severity=error completions/macharden.bash | |
| - name: Shell Syntax Validation | |
| run: | | |
| echo "Checking native Zsh sources..." | |
| for file in bin/macharden lib/*.sh tests/*.sh; do | |
| echo -n "Checking $file ... " | |
| zsh -n "$file" | |
| echo "OK" | |
| done | |
| zsh -n scripts/demo_fixture.sh | |
| bash -n completions/macharden.bash | |
| - name: Execute Test Runner | |
| run: | | |
| chmod +x bin/macharden tests/test_runner.sh tests/test_checks.sh | |
| ./tests/test_runner.sh | |
| - name: Test CLI Interface (--help and --version) | |
| run: | | |
| ./bin/macharden --help | |
| ./bin/macharden --version | |
| - name: Run Dry-Run macOS Security Scan | |
| if: runner.os == 'macOS' | |
| run: | | |
| echo "Executing macharden scans on macOS runner..." | |
| # Terminal report summary (exit 1 means failed checks, not a scanner crash) | |
| set +e | |
| ./bin/macharden -q | |
| SCAN_EC=$? | |
| if [ "$SCAN_EC" -gt 1 ]; then | |
| echo "macharden crashed with exit $SCAN_EC" | |
| exit "$SCAN_EC" | |
| fi | |
| echo "Scan completed with exit $SCAN_EC (0=clean, 1=findings)" | |
| # Markdown report generation (exit 0=clean, 1=findings) | |
| ./bin/macharden -c hardening -f markdown -o audit_hardening.md || true | |
| test -f audit_hardening.md || { echo "audit_hardening.md not created"; exit 1; } | |
| head -n 20 audit_hardening.md | |
| # JSON report generation (exit 0=clean, 1=findings) | |
| ./bin/macharden -c network -f json -o audit_network.json || true | |
| test -f audit_network.json || { echo "audit_network.json not created"; exit 1; } | |
| python3 -m json.tool audit_network.json > /dev/null || { echo "audit_network.json invalid"; exit 1; } | |
| # Remediation script generation (exit 0=clean, 1=findings) | |
| ./bin/macharden --generate-fix test_remediation.sh || true | |
| test -x test_remediation.sh || { echo "test_remediation.sh not executable"; exit 1; } | |
| bash -n test_remediation.sh || { echo "test_remediation.sh syntax error"; exit 1; } | |
| zsh -n test_remediation.sh || { echo "test_remediation.sh zsh syntax error"; exit 1; } | |
| echo "Dry-run scan and remediation verification passed!" |