Skip to content

ci: simplify workflows, enable dev branch, and adopt self-repository syntax - #64

Merged
dmkarthi merged 4 commits into
OpenVisualCloud:devfrom
roshan-ku:ci/simplify-workflows
Sep 29, 2026
Merged

dmkarthi merged 4 commits into
OpenVisualCloud:devfrom
roshan-ku:ci/simplify-workflows

Conversation

@roshan-ku

Copy link
Copy Markdown
Contributor

Summary

Follow-up to the branching-strategy discussion. Cleans up and hardens the GitHub Actions workflows.

Changes

  • Run on dev: added dev to branch triggers for CI, Pull Request, and Scorecard so they run equivalently to main.
  • Remove scan_on_demand.yml: redundant now that Coverity (weekly + manual) and CI/PR analysis steps cover scanning.
  • Remove "Clean up previous run" step: leftover from the old self-hosted runner; GitHub-hosted runners are ephemeral.
  • Self-repository syntax: converted all local action refs from uses: ./... to uses: $/... for fully-pinned policy enforcement (29 refs across 4 workflows).

Notes

  • The Coverity workflow genuinely runs Coverity; github/codeql-action/upload-sarif is just the generic SARIF uploader (category coverity), not CodeQL.
  • No standalone CodeQL analysis workflow exists yet — can add one if desired.

- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
  SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
  daily_build, and pull_request workflows; GitHub runners start clean.
Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.
- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
  triggered on PR + push to main/dev, weekly, and manual. Consolidates the
  approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
  verified) running git-history and directory scans; wire Gitleaks Scan
  into the CI and daily build workflows. Folds in the Gitleaks PR.
…odes

Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.

@dmkarthi dmkarthi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@dmkarthi
dmkarthi merged commit b4ecd6f into OpenVisualCloud:dev Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants