8031389a67
* chore: add GitHub CodeQL analysis to CI workflow Enable automated security scanning with GitHub CodeQL to detect potential vulnerabilities in Python code. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> * chore: run CodeQL analysis on pull requests Co-authored-by: Cursor <cursoragent@cursor.com> * Add checks and statuses read permissions for dependabot auto-merge. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
93 lines
2.7 KiB
YAML
93 lines
2.7 KiB
YAML
---
|
|
name: CI/CD
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
branches:
|
|
- main
|
|
types:
|
|
- opened
|
|
- synchronize
|
|
- reopened
|
|
workflow_dispatch: # checkov:skip=CKV_GHA_7:workflow_dispatch inputs are required for manual runs
|
|
inputs:
|
|
workflow:
|
|
required: true
|
|
type: choice
|
|
options:
|
|
- lint-and-test
|
|
- docs-deploy
|
|
description: Choose the workflow to run
|
|
default: lint-and-test
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
shell: bash -euo pipefail {0}
|
|
working-directory: .
|
|
jobs:
|
|
python-lint-and-scan:
|
|
if: >
|
|
github.event_name == 'push'
|
|
|| github.event_name == 'pull_request'
|
|
|| (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test')
|
|
permissions:
|
|
contents: read
|
|
uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-lint-and-scan.yml@main # zizmor: ignore[unpinned-uses]
|
|
with:
|
|
package-path: .
|
|
runs-on: windows-latest
|
|
python-test:
|
|
if: >
|
|
github.event_name == 'push'
|
|
|| github.event_name == 'pull_request'
|
|
|| (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test')
|
|
permissions:
|
|
contents: read
|
|
uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-test.yml@main # zizmor: ignore[unpinned-uses]
|
|
with:
|
|
package-path: .
|
|
runs-on: windows-latest
|
|
python-docs-deploy:
|
|
if: >
|
|
github.event_name == 'push'
|
|
|| (github.event_name == 'workflow_dispatch' && inputs.workflow == 'docs-deploy')
|
|
permissions:
|
|
contents: write
|
|
uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-mkdocs-gh-deploy.yml@main # zizmor: ignore[unpinned-uses]
|
|
with:
|
|
package-path: .
|
|
runs-on: ubuntu-slim
|
|
secrets:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
github-codeql-analysis:
|
|
if: >
|
|
github.event_name == 'push'
|
|
|| github.event_name == 'pull_request'
|
|
|| (github.event_name == 'workflow_dispatch' && inputs.workflow == 'lint-and-test')
|
|
permissions:
|
|
contents: read
|
|
security-events: write
|
|
actions: read
|
|
uses: dceoy/gh-actions-for-devops/.github/workflows/github-codeql-analysis.yml@main # zizmor: ignore[unpinned-uses]
|
|
with:
|
|
language: >
|
|
["python"]
|
|
dependabot-auto-merge:
|
|
if: >
|
|
github.event_name == 'pull_request' && github.actor == 'dependabot[bot]'
|
|
needs:
|
|
- python-lint-and-scan
|
|
- python-test
|
|
uses: dceoy/gh-actions-for-devops/.github/workflows/dependabot-auto-merge.yml@main # zizmor: ignore[unpinned-uses]
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
actions: read
|
|
checks: read
|
|
statuses: read
|
|
with:
|
|
unconditional: true
|