Skip to content

Commit 0ae048d

Browse files
committed
chore: add ci-security workflow
1 parent 0d46f2a commit 0ae048d

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed

.github/workflows/ci-security.yml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
on:
2+
push:
3+
branches:
4+
- main
5+
pull_request:
6+
merge_group:
7+
8+
name: Security
9+
10+
permissions:
11+
contents: read
12+
actions: read
13+
security-events: write
14+
15+
env:
16+
SEMGREP_ENABLE_VERSION_CHECK: 'false'
17+
18+
jobs:
19+
ensure-pinned-actions:
20+
runs-on: ubuntu-latest
21+
steps:
22+
- name: Checkout code
23+
uses: actions/checkout@v4
24+
- name: Ensure SHA pinned actions
25+
uses: zgosalvez/github-actions-ensure-sha-pinned-actions@9e9574ef04ea69da568d6249bd69539ccc704e74 # v4.0.0
26+
with:
27+
allowlist: |
28+
actions/
29+
PostHog/

0 commit comments

Comments
 (0)