Repository navigation
Ci/simplify workflows (#4) - #66
Merged
Merged
Conversation
* ci: remove on-demand scan and redundant clean step
- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
daily_build, and pull_request workflows; GitHub runners start clean.
* ci: use self-repository syntax for local actions
Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.
* ci: add CodeQL advanced workflow and Gitleaks CLI scan
- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
triggered on PR + push to main/dev, weekly, and manual. Consolidates the
approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
verified) running git-history and directory scans; wire Gitleaks Scan
into the CI and daily build workflows. Folds in the Gitleaks PR.
* ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes
Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.
* ci: restore './' prefix for local composite action references
Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.
All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
---------
Co-authored-by: sunilnom <sunil.nomeshwar.naik@intel.com>
roshan-ku
added a commit
to roshan-ku/directview-led-software-toolkit
that referenced
this pull request
Sep 30, 2026
This reverts commit 78d26b9.
dmkarthi
pushed a commit
that referenced
this pull request
Sep 30, 2026
This reverts commit 78d26b9. StepSecurity false positive, not a GitHub Actions error. uses: $/.github/actions/analysis/coverity is the new GitHub self-repository syntax. GitHub resolves it to the exact commit currently running, so it is inherently pinned. It requires runner 2.336.0+. StepSecurity has not recognized $/... yet and incorrectly classifies it as an unpinned third-party action. Do not add @sha; that would defeat the self-repository syntax and may be invalid. Recommended action: keep the $/... references and suppress or ignore this StepSecurity finding until StepSecurity adds support.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Local action references had been written as '$/.github/actions/...', which is not valid GitHub Actions syntax; a local action path must start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard classified all 26 internal references as unpinned third-party actions, dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party GitHubAction dependencies pinned") and the overall score to 8.3.
All remaining external actions are already pinned by SHA, so this restores Pinned-Dependencies to a passing state.
Description
Checklist
Code Quality
Testing
Review Readiness
Documentation
Security
PR Type
What kind of change does this PR introduce?