diff --git a/.github/workflows/openapi.yml b/.github/workflows/openapi.yml index f45a708..51db9a6 100644 --- a/.github/workflows/openapi.yml +++ b/.github/workflows/openapi.yml @@ -6,7 +6,7 @@ on: jobs: build: - name: Run Spectral + name: Build OpenAPI document for pygeoapi configuration and addicted security runs-on: ubuntu-latest steps: # Check out the repository @@ -33,24 +33,32 @@ jobs: poetry install poetry run fastgeoapi openapi + spectral-oas: + runs-on: ubuntu-latest + needs: build + steps: # Create OAS3 ruleset - name: Create OAS 3 run: | echo 'extends: ["spectral:oas"]' > .spectral.oas3.yaml - # Create OWASP API Security 10 ruleset - - name: Create OWASP API Security 10 - run: | - npm install -g @stoplight/spectral-owasp-ruleset@latest - echo 'extends: ["https://unpkg.com/@stoplight/spectral-owasp-ruleset/dist/ruleset.mjs"]' > .spectral.owasp-top-10.yaml - - # Run Spectral for OWASP Top 10 + # Run Spectral for OAS3 - name: Run Spectral for OAS3 uses: stoplightio/spectral-action@latest with: file_glob: "pygeoapi-openapi.json" spectral_ruleset: ".spectral.oas3.yaml" + spectral-owasp: + runs-on: ubuntu-latest + needs: build + steps: + # Create OWASP API Security 10 ruleset + - name: Create OWASP API Security 10 + run: | + npm install -g @stoplight/spectral-owasp-ruleset@latest + echo 'extends: ["https://unpkg.com/@stoplight/spectral-owasp-ruleset/dist/ruleset.mjs"]' > .spectral.owasp-top-10.yaml + # Run Spectral for OWASP Top 10 - name: Run Spectral for OWASP top 10 uses: stoplightio/spectral-action@latest