fix: revert security-scan.yml to inline, not a reusable-workflow call #8

Merged
james merged 1 commit from fix/inline-security-scan into main 2026-09-07 20:10:17 +00:00
Owner

Same fix as colibrisec/balam#20 -- calling forgejo-workflows' shared security-scan reusable workflow silently stopped ojo-forgejo's PR comments from posting. Reverting to the known-working inline form.

Same fix as colibrisec/balam#20 -- calling forgejo-workflows' shared security-scan reusable workflow silently stopped ojo-forgejo's PR comments from posting. Reverting to the known-working inline form.
fix: revert security-scan.yml to inline, not a reusable-workflow call
All checks were successful
test / test (pull_request) Successful in 8s
security-scan / security-scan (pull_request) Successful in 1m1s
4496e99912
Calling forgejo-workflows' shared security-scan reusable workflow
silently broke ojo-forgejo's PR comments: they posted on every PR
through #12, and on zero PRs since #13 -- the exact commit that
converted this to uses:. No visibility into forgejo-runner internals to
know why a nested custom action loses the PR context when invoked
through a reusable workflow, but the correlation is total across 7+
PRs. Reverting to the known-working inline form; renovate.yml is
unaffected (it never posts PR comments) and stays on the shared
workflow.

🔎 ojo scan results

No findings.

<!-- ojo-scan-summary --> ### 🔎 ojo scan results No findings.
james merged commit cf9d354832 into main 2026-09-07 20:10:17 +00:00
james deleted branch fix/inline-security-scan 2026-09-07 20:10:18 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam-forgejo!8
No description provided.