Skip to content

docs: overhaul demo gif, dashboard visual, and README marketing matrix #16

docs: overhaul demo gif, dashboard visual, and README marketing matrix

docs: overhaul demo gif, dashboard visual, and README marketing matrix #16

Workflow file for this run

name: CI
on:
push:
branches: [ main, master ]
pull_request:
branches: [ main, master ]
workflow_dispatch:
jobs:
test:
name: Build & Test (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ macos-latest, ubuntu-latest ]
env:
MACHAR_ALLOW_NON_DARWIN: 1
steps:
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Linux Dependencies
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y zsh bash shellcheck python3
- name: Setup macOS Dependencies
if: runner.os == 'macOS'
run: |
if ! command -v shellcheck &>/dev/null; then
brew install shellcheck
fi
- name: ShellCheck Bash Integration
run: |
echo "Running ShellCheck on the Bash completion integration..."
shellcheck --severity=error completions/macharden.bash
- name: Shell Syntax Validation
run: |
echo "Checking native Zsh sources..."
for file in bin/macharden lib/*.sh tests/*.sh; do
echo -n "Checking $file ... "
zsh -n "$file"
echo "OK"
done
zsh -n scripts/demo_fixture.sh
bash -n completions/macharden.bash
- name: Execute Test Runner
run: |
chmod +x bin/macharden tests/test_runner.sh tests/test_checks.sh
./tests/test_runner.sh
- name: Test CLI Interface (--help and --version)
run: |
./bin/macharden --help
./bin/macharden --version
- name: Run Dry-Run macOS Security Scan
if: runner.os == 'macOS'
run: |
echo "Executing macharden scans on macOS runner..."
# Terminal report summary (exit 1 means failed checks, not a scanner crash)
set +e
./bin/macharden -q
SCAN_EC=$?
if [ "$SCAN_EC" -gt 1 ]; then
echo "macharden crashed with exit $SCAN_EC"
exit "$SCAN_EC"
fi
echo "Scan completed with exit $SCAN_EC (0=clean, 1=findings)"
# Markdown report generation (exit 0=clean, 1=findings)
./bin/macharden -c hardening -f markdown -o audit_hardening.md || true
test -f audit_hardening.md || { echo "audit_hardening.md not created"; exit 1; }
head -n 20 audit_hardening.md
# JSON report generation (exit 0=clean, 1=findings)
./bin/macharden -c network -f json -o audit_network.json || true
test -f audit_network.json || { echo "audit_network.json not created"; exit 1; }
python3 -m json.tool audit_network.json > /dev/null || { echo "audit_network.json invalid"; exit 1; }
# Remediation script generation (exit 0=clean, 1=findings)
./bin/macharden --generate-fix test_remediation.sh || true
test -x test_remediation.sh || { echo "test_remediation.sh not executable"; exit 1; }
bash -n test_remediation.sh || { echo "test_remediation.sh syntax error"; exit 1; }
zsh -n test_remediation.sh || { echo "test_remediation.sh zsh syntax error"; exit 1; }
echo "Dry-run scan and remediation verification passed!"