Skip to content

ci: give the dev branch the same workflow coverage as main (#60) - #62

Closed
dmkarthi wants to merge 1 commit into
devfrom
main
Closed

dmkarthi wants to merge 1 commit into
devfrom
main

Conversation

@dmkarthi

Copy link
Copy Markdown
Collaborator
  • ci: give the dev branch the same workflow coverage as main

Add dev to the push filters of Continuous Integration and OpenSSF Scorecard, and to the pull_request base filter of the Pull Request workflow.

Scheduled workflows only ever run on the default branch, so Daily Build and Coverity Scan now fan out over a main/dev matrix, check out the matrix branch explicitly and tag their artifacts with it. Coverity passes the scanned ref and sha to upload-sarif so dev findings are not attributed to main, and Scorecard only publishes results from the default branch, which is all the Scorecard API accepts.

  • ci: run daily build and coverity on default branch, cache from main and dev

Description

Checklist

Code Quality

  • Code follows project style guidelines
  • No unnecessary debug logs or commented-out code
  • No hardcoded values / secrets

Testing

  • Unit test added/modified accordingly
  • Perform manual basic sanity testing at system level

Review Readiness

  • PR title and description are clear and meaningful
  • Story/Task IDs are linked

Documentation

  • README or relevant docs updated (if applicable)

Security

  • No sensitive data exposed (keys, passwords, tokens)
  • Input validation added where needed

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Documentation content changes
  • Testing
  • Other... Please describe:

* ci: give the dev branch the same workflow coverage as main

Add dev to the push filters of Continuous Integration and OpenSSF
Scorecard, and to the pull_request base filter of the Pull Request
workflow.

Scheduled workflows only ever run on the default branch, so Daily Build
and Coverity Scan now fan out over a main/dev matrix, check out the
matrix branch explicitly and tag their artifacts with it. Coverity
passes the scanned ref and sha to upload-sarif so dev findings are not
attributed to main, and Scorecard only publishes results from the
default branch, which is all the Scorecard API accepts.

* ci: run daily build and coverity on default branch, cache from main and dev
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@dmkarthi dmkarthi closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants