ci: github workflow linter and security validator#393
ci: github workflow linter and security validator#393Shurtu-gal wants to merge 30 commits intoasyncapi:masterfrom
Conversation
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
@asyncapi/bounty_team |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
Nearly everything is done. Only thing left is to integrate zizmor with validate workflow. |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
Everything in zizmor passes now -> |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
Actionlint problems fixed. Although $GITHUB_OUTPUT is safe inherently, doesn't hurt to be cautious. Ref: |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
@derberg this is ready for review now. Some questions:
cc: @Florence-Njeri as it is security related. |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
Stuff is already working in a fantastic manner: |
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
|
Future todo: |
Florence-Njeri
left a comment
There was a problem hiding this comment.
All the changes look good to me, just one question @Shurtu-gal
Signed-off-by: Shurtu-gal <ashishpadhy1729@gmail.com>
Progress Tracker
Validate workflow files
The flow would be ->
Github workflows
aeworxetinstead of checking for either. Test PR and Test Workflow Run.Scripts
Actions
Add actions-permission monitoring to the issues.
Still need to verify
Related issue(s)
Fixes #388