Skip to content

SEC-090: Automated trusted workflow pinning (2024-06-24) #554

SEC-090: Automated trusted workflow pinning (2024-06-24)

SEC-090: Automated trusted workflow pinning (2024-06-24) #554

Workflow file for this run

---
name: Vendor Dependencies Check
on:
pull_request:
types: ['opened', 'synchronize']
paths:
- '.github/workflows/depscheck.yaml'
- 'vendor/**'
- '**.go'
jobs:
depscheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- uses: actions/setup-go@cdcb36043654635271a94b9a6d1392de5bb323a7 # v5.0.1
with:
go-version-file: .go-version
- run: bash scripts/gogetcookie.sh
- run: make tools
- run: make depscheck
save-artifacts-on-fail:
if: ${{ needs.depscheck.result }} == 'failure'
uses: ./.github/workflows/save-artifacts.yaml
comment-on-fail:
if: ${{ needs.depscheck.result }} == 'failure'
uses: ./.github/workflows/comment-failure.yaml