Skip to content

ci: restore generated blocking security scans - #3792

Draft
KooshaPari wants to merge 1 commit into
tailcallhq:mainfrom
KooshaPari:ci/baseline-workflow-repair-main-20260731
Draft

ci: restore generated blocking security scans#3792
KooshaPari wants to merge 1 commit into
tailcallhq:mainfrom
KooshaPari:ci/baseline-workflow-repair-main-20260731

Conversation

@KooshaPari

Copy link
Copy Markdown

Scope

This replacement PR is rebuilt from current main and changes only the CI workflow generator, its generated ci.yml, and focused regression coverage. It supersedes #3791, which was conflict-dirty after main advanced.

Security controls

  • PR-only Dependency Review with contents: read and immutable actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 (v5.0.0).
  • Blocking Trivy filesystem/dependency vulnerability scan with contents: read, credentialless checkout, HIGH/CRITICAL severity, unfixed findings included, and exit-code: 1; immutable aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 (v0.36.0).

Provenance

  • Base: 43d6be453342abbffaea194837665a7a781b823c (main)
  • Head: cb31a659909cb655a8fef9fcc843c461394b2939

Validation

  • CARGO_NET_OFFLINE=true CARGO_TARGET_DIR=/tmp/forgecode-security-main-target cargo test -p forge_ci --test ci generated_ci_preserves_blocking_pr_security_scans -- --exact --nocapture
  • CI=1 CARGO_NET_OFFLINE=true CARGO_TARGET_DIR=/tmp/forgecode-security-main-target cargo test -p forge_ci --test ci generate -- --exact --nocapture
  • Scoped rustfmt --check for changed Rust files.
  • actionlint .github/workflows/ci.yml emitted only baseline informational shellcheck notices outside this scope.

No A+ or merge claim is made; no branch-protection bypass is requested.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


KooshaPari seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants