Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: actions permissions and upgrade to 1.9.1 #22

Merged
merged 3 commits into from
Feb 17, 2025
Merged

Conversation

luohoufu
Copy link
Contributor

@luohoufu luohoufu commented Feb 6, 2025

What does this PR do

This pull request includes updates to the GitHub Actions workflow configuration file .github/workflows/osv-scanner.yml. The changes primarily focus on adjusting permissions and updating the reusable workflow reference.

Updates to GitHub Actions workflow configuration:

  • Added actions: read permission to allow uploading SARIF files to CodeQL.
  • Updated the comment for contents: read permission to clarify it only needs to read contents.
  • Changed the reusable workflow reference from version 1f1242919d8a60496dd1874b24b62b2370ed4c78 to v1.9.1.

Rationale for this change

Standards checklist

  • The PR title is descriptive
  • The commit messages are semantic
  • Necessary tests are added
  • Updated the release notes
  • Necessary documents have been added if this is a new feature
  • Performance tests checked, no obvious performance degradation

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@@ -16,14 +16,16 @@ on:
branches: [ "main" ]

permissions:
# Required to upload SARIF file to CodeQL. See: https://github.com/github/codeql-action/issues/2117
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please let me know where you found the error reported by the linked issue? Looks like our CIs are working as expected.

Or this issue only happens after bumping the action from "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@1f1242919d8a60496dd1874b24b62b2370ed4c78" to "google/osv-scanner-action/.github/workflows/[email protected]"?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

when use [email protected] the permissions need changed

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@luohoufu luohoufu requested a review from SteveLauC February 17, 2025 02:07
@medcl medcl merged commit 87b9e51 into main Feb 17, 2025
6 checks passed
@medcl medcl deleted the fix_osv_scanner branch February 17, 2025 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants