From a623c8e1f1b1c0c984853d1fa2fcec5b1bec0a07 Mon Sep 17 00:00:00 2001 From: ChiaAutomation <85647627+ChiaAutomation@users.noreply.github.com> Date: Thu, 21 Mar 2024 13:36:07 -0500 Subject: [PATCH] Update Managed Files (#151) * Update dep-review * Update go-test * Remove old test wf --------- Co-authored-by: StartToaster --- .github/workflows/dependency-review.yml | 14 +++++++++----- .github/workflows/{lint.yaml => go-test.yml} | 7 ++++--- 2 files changed, 13 insertions(+), 8 deletions(-) rename .github/workflows/{lint.yaml => go-test.yml} (64%) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index b0dedc4..3bc3e1a 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,10 +1,11 @@ +# Managed by repo-content-updater # Dependency Review Action # # This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging. # # Source repository: https://github.com/actions/dependency-review-action # Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement -name: 'Dependency Review' +name: "🚨 Dependency Review" on: [pull_request] permissions: @@ -14,7 +15,10 @@ jobs: dependency-review: runs-on: ubuntu-latest steps: - - name: 'Checkout Repository' - uses: actions/checkout@v3 - - name: 'Dependency Review' - uses: actions/dependency-review-action@v3 + - name: "Checkout Repository" + uses: actions/checkout@v4 + + - name: "Dependency Review" + uses: actions/dependency-review-action@v4 + with: + deny-licenses: AGPL-1.0-only, AGPL-1.0-or-later, AGPL-1.0-or-later, AGPL-3.0-or-later, GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later diff --git a/.github/workflows/lint.yaml b/.github/workflows/go-test.yml similarity index 64% rename from .github/workflows/lint.yaml rename to .github/workflows/go-test.yml index f5eae4b..0a8cb06 100644 --- a/.github/workflows/lint.yaml +++ b/.github/workflows/go-test.yml @@ -1,4 +1,4 @@ -name: Test/Lint/Fmt/Vet +name: Go Test on: push: branches: @@ -9,9 +9,10 @@ jobs: test: runs-on: ubuntu-latest container: golang:1 - env: - GOFLAGS: "-buildvcs=false" steps: + - name: Mark git directory safe + uses: Chia-Network/actions/git-mark-workspace-safe@main + - uses: actions/checkout@v4 - name: Test