Skip to content

ci: restore generated blocking security scans - #3794

Open
KooshaPari wants to merge 1 commit into
tailcallhq:mainfrom
KooshaPari:ci/security-scan-restore-current-20260731
Open

ci: restore generated blocking security scans#3794
KooshaPari wants to merge 1 commit into
tailcallhq:mainfrom
KooshaPari:ci/security-scan-restore-current-20260731

Conversation

@KooshaPari

Copy link
Copy Markdown

Recreates the reviewed security restoration from #3792 on current upstream main 74db8b5b.

  • Restores blocking PR-only Dependency Review with read-only contents permission.
  • Restores blocking Trivy filesystem/dependency vulnerability scan with pinned actions and non-persistent checkout credentials.
  • Updates the Rust generator, emitted workflow, and parity assertion together.

Validation: cargo test -p forge_ci --test ci (8 passed); focused security invariant (1 passed); git diff --check. actionlint is unchanged from baseline: six existing SC2086 infos in generated release steps.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


KooshaPari seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants