chore(ci): Maximize CI/CD values (Dependabot & Permissions) - #1
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bcd82a5f73
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -1,19 +1,17 @@ | |||
| name: BoJ Server Build Trigger | |||
There was a problem hiding this comment.
Add the required SPDX header to this workflow
Because this change edits .github/workflows/boj-build.yml, it will trigger .github/workflows/workflow-linter.yml. Its Check SPDX Headers step (lines 27-40) fails any workflow whose first line is not an SPDX comment, and this file still starts with name:. As written, any push or PR containing this commit will leave CI red until the header is added.
Useful? React with 👍 / 👎.
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 |
There was a problem hiding this comment.
Pin
actions/checkout to a full commit SHA
This PR also triggers .github/workflows/workflow-linter.yml's Check SHA-Pinned Actions step (lines 61-77), which rejects any uses: entry that is not pinned to a 40-character SHA. actions/checkout@v4 still matches that failure case here, so the workflow linter will continue to fail on this commit.
Useful? React with 👍 / 👎.
Bumps [toml](https://github.com/toml-rs/toml) from 0.8.23 to 1.1.2+spec-1.1.0. - [Commits](toml-rs/toml@toml-v0.8.23...toml-v1.1.2) --- updated-dependencies: - dependency-name: toml dependency-version: 1.1.2+spec-1.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This automated PR updates your CI/CD configurations to maximize value and security.
github-actionsis monitored for updates.permissions: read-allto workflows missing explicit permissions.