--- name: CI/CD on: push: branches: - main pull_request: branches: - main types: - opened - synchronize - reopened workflow_dispatch: # checkov:skip=CKV_GHA_7:workflow_dispatch inputs are required for manual runs inputs: workflow: required: true type: choice options: - lint-and-test - docs-deploy description: Choose the workflow to run default: lint-and-test permissions: contents: read defaults: run: shell: bash -euo pipefail {0} working-directory: . jobs: python-lint-and-scan: if: > github.event_name == 'push' || github.event_name == 'pull_request' || (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test') permissions: contents: read uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-lint-and-scan.yml@main # zizmor: ignore[unpinned-uses] with: package-path: . runs-on: windows-latest python-test: if: > github.event_name == 'push' || github.event_name == 'pull_request' || (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test') permissions: contents: read uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-test.yml@main # zizmor: ignore[unpinned-uses] with: package-path: . runs-on: windows-latest python-docs-deploy: if: > github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && inputs.workflow == 'docs-deploy') permissions: contents: write uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-mkdocs-gh-deploy.yml@main # zizmor: ignore[unpinned-uses] with: package-path: . runs-on: ubuntu-slim secrets: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} github-codeql-analysis: if: > github.event_name == 'push' || github.event_name == 'pull_request' || (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test') permissions: contents: read security-events: write actions: read uses: dceoy/gh-actions-for-devops/.github/workflows/github-codeql-analysis.yml@main # zizmor: ignore[unpinned-uses] with: language: > ["python"] dependabot-auto-merge: if: > github.event_name == 'pull_request' && github.actor == 'dependabot[bot]' needs: - python-lint-and-scan - python-test uses: dceoy/gh-actions-for-devops/.github/workflows/dependabot-auto-merge.yml@main # zizmor: ignore[unpinned-uses] permissions: contents: write pull-requests: write actions: read checks: read statuses: read with: unconditional: true