fix: correct security-scan.yml reusable-workflow call #13

Merged
james merged 2 commits from fix/security-scan-input into main 2026-09-06 21:55:49 +00:00
Owner

security-scan.yml on main currently passes with: repository: colibrisec/ojo-forgejo � the wrong input key (the reusable workflow declared product-name, not repository) and the wrong value (this repo's own name, not ojo-forgejo's). This got copy-pasted identically into all three calling repos.

Depends on colibrisec/forgejo-workflows#3, which removes the input entirely (the reusable workflow now derives the repo name from github.repository), so this also drops the now-unnecessary with: block from both security-scan.yml and renovate.yml and updates the pin to that commit.

Also switches both from secrets: inherit to explicit secret mapping (only the specific secrets each reusable workflow declares needing, not every secret this repo has).

`security-scan.yml` on main currently passes `with: repository: colibrisec/ojo-forgejo` � the wrong input key (the reusable workflow declared `product-name`, not `repository`) and the wrong value (this repo's own name, not ojo-forgejo's). This got copy-pasted identically into all three calling repos. Depends on colibrisec/forgejo-workflows#3, which removes the input entirely (the reusable workflow now derives the repo name from `github.repository`), so this also drops the now-unnecessary `with:` block from both `security-scan.yml` and `renovate.yml` and updates the pin to that commit. Also switches both from `secrets: inherit` to explicit secret mapping (only the specific secrets each reusable workflow declares needing, not every secret this repo has).
security-scan.yml was passing repository: colibrisec/ojo-forgejo — the wrong
input name (the reusable workflow declares product-name, not repository)
and the wrong value (balam's own name, not ojo-forgejo's). This was copied
identically into all three calling repos; this fixes balam's copy.

Also switches both workflows here from secrets: inherit to an explicit
secrets: mapping, so the reusable workflow only receives the specific
secrets it declares needing, not every secret this repo has.
fix: use simplified input-free reusable workflows, correct SHA pin
All checks were successful
security-scan / scan-1 (pull_request) Successful in 23s
security-scan / scan (pull_request) Successful in 0s
test / web (pull_request) Successful in 55s
test / go (pull_request) Successful in 2m18s
a0757d031a
Supersedes the earlier product-name/repository input-based version: the
shared workflows (colibrisec/forgejo-workflows) now derive the calling
repo's name from github.repository internally, so callers need nothing
but uses: + secrets:.
james merged commit f3584afa49 into main 2026-09-06 21:55:49 +00:00
james deleted branch fix/security-scan-input 2026-09-06 21:55:50 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!13
No description provided.