Skip to content

Commit

Permalink
chore(ci): make scorecard happier (#65)
Browse files Browse the repository at this point in the history
* chore(ci): make scorecard happier
* chore: add codeowners

J:DEF-3650
  • Loading branch information
JPLachance authored Jan 14, 2025
1 parent a203438 commit eb8d697
Show file tree
Hide file tree
Showing 3 changed files with 22 additions and 0 deletions.
6 changes: 6 additions & 0 deletions .github/workflows/java-maven-openjdk11-codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,16 @@ on:
required: false
type: string

permissions: { }

jobs:
analyze-java:
uses: coveo/public-actions/.github/workflows/java-maven-openjdk-codeql.yml@main
with:
runs-on: ${{ inputs.runs-on }}
mvn-additional-arguments: ${{ inputs.mvn-arguments }}
jdk-version: 11
permissions:
actions: read
contents: read
security-events: write
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ on:
required: false
type: string

permissions: { }

jobs:
submit-dependencies:
name: Submit dependencies
Expand All @@ -22,3 +24,5 @@ jobs:
runs-on: ${{ inputs.runs-on }}
directory: ${{ inputs.directory }}
jdk-version: 11
permissions:
contents: write
12 changes: 12 additions & 0 deletions CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,2 +1,14 @@
.github/workflows/dependency-review.yml @coveo/dev-tooling-reviewers-1 @coveo/dev-tooling-reviewers-2 @coveo/dev-tooling-reviewers-3
audit-renovate-config/** @coveo/dev-tooling @coveo/r-d-security-defence @coveo/cloud-intelligence

.github/workflows/actions-codeql.yml @coveo/r-d-security-defence
.github/workflows/dependency-review.yml @coveo/r-d-security-defence
.github/workflows/dependency-review-v2.yml @coveo/r-d-security-defence
.github/workflows/java-maven-openjdk11-codeql.yml @coveo/r-d-security-defence
.github/workflows/java-maven-openjdk11-dependency-submission.yml @coveo/r-d-security-defence
.github/workflows/java-maven-openjdk-codeql.yml @coveo/r-d-security-defence
.github/workflows/java-maven-openjdk-dependency-review.yml @coveo/r-d-security-defence
.github/workflows/java-maven-openjdk-dependency-submission.yml @coveo/r-d-security-defence
.github/workflows/scorecard.yml @coveo/r-d-security-defence
.github/workflows/test-actions-codeql.yml @coveo/r-d-security-defence
.github/workflows/test-dependency-review.yml @coveo/r-d-security-defence

0 comments on commit eb8d697

Please sign in to comment.