-
Notifications
You must be signed in to change notification settings - Fork 5.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fotze #2596
Closed
YodaDarkside187
wants to merge
1,350
commits into
actions:updae_azure_python_cache
from
YodaDarkside187:main
Closed
Fotze #2596
YodaDarkside187
wants to merge
1,350
commits into
actions:updae_azure_python_cache
from
YodaDarkside187:main
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Update all Pages starter workflows to use upload-pages-artifact@v2
move gem workflow to ruby/setup-ruby, same as ruby
Update Hugo version and switch to Dart Sass
Update denoland/setup-deno workflow
CodeQL - add runner size document hints
Update setup-go and latest go versions
Update Dependency Review Action to V3
…ction use intermediate environment variables to avoid risks of script injection
…-evans/close-issue-3 Bump peter-evans/close-issue from 2 to 3
Update elixir.yml - fix default build and bump version
Update Mayhem for API to reference new site
Update labeler.yml for v5
Update stale.yml to only use workflow_dispatch
- Bump version hashes to use `gradle/actions/[email protected]` - Bump version hash to use `gradle/actions/[email protected]`
Update for `gradle/[email protected]` release
* Update soos-dast-scan.yml * Update soos-dast-scan.yml * Update soos-dast-scan.yml * Update soos-dast-scan.yml
* Add Debricked starter workflow * Add permissions section * Remove schedule * Fix review comments --------- Co-authored-by: Alexis Abril <[email protected]>
Spurious intermittent timeouts are no longer expected on Swift.
CodeQL: Remove Swift 2h timeout
* google: update workflow versions and instructions * Pin hashes
CodeQL - Add unique workflow name `CodeQL Advanced` vs default setup's `CodeQL`
* Added appknox.yml for code scanning * Create appknox.json * Create appknox.svg * Update appknox.json * Update appknox.svg * Rename appknox.json to appknox.properties.json * Update appknox.yml * Update appknox.yml * Update appknox.properties.json * Formatting yml
Ensure suppressed warnings don't make it into the SARIF.
Fix linting errors (remove whitespace).
Fix more whitespace issues.
Update eslint.yml
Create appknox.json Create appknox.svg Update appknox.json Update appknox.svg Rename appknox.json to appknox.properties.json Update appknox.yml Update appknox.yml Update appknox.properties.json Formatting yml Removed preview mode from appknox scanner Removed preview mode from appknox scanner Add Appknox starter workflow (#2447) * Added appknox.yml for code scanning * Create appknox.json * Create appknox.svg * Update appknox.json * Update appknox.svg * Rename appknox.json to appknox.properties.json * Update appknox.yml * Update appknox.yml * Update appknox.properties.json * Formatting yml removed preview mode removed preview mode precommit lint
Add jfrog-sast flow
github-actions
bot
added
the
code-scanning
Related to workflows that show on the Code Scanning setup page
label
Nov 12, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pre-requisites
Please note that at this time we are only accepting new starter workflows for Code Scanning. Updates to existing starter workflows are fine.
Tasks
For all workflows, the workflow:
.yml
file with the language or platform as its filename, in lower, kebab-cased format (for example,docker-image.yml
). Special characters should be removed or replaced with words as appropriate (for example, "dotnet" instead of ".NET").GITHUB_TOKEN
so that the workflow runs successfully.For CI workflows, the workflow:
ci
directory.ci/properties/*.properties.json
file (for example,ci/properties/docker-publish.properties.json
).push
tobranches: [ $default-branch ]
andpull_request
tobranches: [ $default-branch ]
.release
withtypes: [ created ]
.docker-publish.yml
).For Code Scanning workflows, the workflow:
code-scanning
directory.code-scanning/properties/*.properties.json
file (for example,code-scanning/properties/codeql.properties.json
), with properties set as follows:name
: Name of the Code Scanning integration.creator
: Name of the organization/user producing the Code Scanning integration.description
: Short description of the Code Scanning integration.categories
: Array of languages supported by the Code Scanning integration.iconName
: Name of the SVG logo representing the Code Scanning integration. This SVG logo must be present in theicons
directory.push
tobranches: [ $default-branch, $protected-branches ]
andpull_request
tobranches: [ $default-branch ]
. We also recommend aschedule
trigger ofcron: $cron-weekly
(for example,codeql.yml
).Some general notes:
actions
organization, or