Skip to content

Ci/simplify workflows (#4) - #66

Merged
dmkarthi merged 1 commit into
OpenVisualCloud:devfrom
roshan-ku:dev
Sep 30, 2026
Merged

dmkarthi merged 1 commit into
OpenVisualCloud:devfrom
roshan-ku:dev

Conversation

@roshan-ku

@roshan-ku roshan-ku commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
  • ci: restore './' prefix for local composite action references

Local action references had been written as '$/.github/actions/...', which is not valid GitHub Actions syntax; a local action path must start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard classified all 26 internal references as unpinned third-party actions, dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party GitHubAction dependencies pinned") and the overall score to 8.3.

All remaining external actions are already pinned by SHA, so this restores Pinned-Dependencies to a passing state.


Description

Checklist

Code Quality

  • Code follows project style guidelines
  • No unnecessary debug logs or commented-out code
  • No hardcoded values / secrets

Testing

  • Unit test added/modified accordingly
  • Perform manual basic sanity testing at system level

Review Readiness

  • PR title and description are clear and meaningful
  • Story/Task IDs are linked

Documentation

  • README or relevant docs updated (if applicable)

Security

  • No sensitive data exposed (keys, passwords, tokens)
  • Input validation added where needed

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Documentation content changes
  • Testing
  • Other... Please describe:

* ci: remove on-demand scan and redundant clean step

- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
  SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
  daily_build, and pull_request workflows; GitHub runners start clean.

* ci: use self-repository syntax for local actions

Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.

* ci: add CodeQL advanced workflow and Gitleaks CLI scan

- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
  triggered on PR + push to main/dev, weekly, and manual. Consolidates the
  approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
  verified) running git-history and directory scans; wire Gitleaks Scan
  into the CI and daily build workflows. Folds in the Gitleaks PR.

* ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes

Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.

* ci: restore './' prefix for local composite action references

Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.

All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.

---------

Co-authored-by: sunilnom <sunil.nomeshwar.naik@intel.com>

@dmkarthi dmkarthi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@dmkarthi
dmkarthi merged commit 78d26b9 into OpenVisualCloud:dev Sep 30, 2026
3 checks passed
roshan-ku added a commit to roshan-ku/directview-led-software-toolkit that referenced this pull request Sep 30, 2026
dmkarthi pushed a commit that referenced this pull request Sep 30, 2026
This reverts commit 78d26b9.

StepSecurity false positive, not a GitHub Actions error.

uses: $/.github/actions/analysis/coverity is the new GitHub self-repository syntax. GitHub resolves it to the exact commit currently running, so it is inherently pinned. It requires runner 2.336.0+.

StepSecurity has not recognized $/... yet and incorrectly classifies it as an unpinned third-party action. Do not add @sha; that would defeat the self-repository syntax and may be invalid.

Recommended action: keep the $/... references and suppress or ignore this StepSecurity finding until StepSecurity adds support.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants