Workflow template repository
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
James Luther 95bdd86dda
Some checks failed
ojo-scan.yml / Merge pull request 'fix: bump renovate job to Node 24, [email protected] requires it' (#5) from fix/renovate-node-version into main (push) Failing after 0s
renovate.yml / Merge pull request 'fix: bump renovate job to Node 24, [email protected] requires it' (#5) from fix/renovate-node-version into main (push) Failing after 0s
Merge pull request 'fix: bump renovate job to Node 24, [email protected] requires it' (#5) from fix/renovate-node-version into main
Reviewed-on: #5
2026-09-11 23:05:12 +00:00
.forgejo/workflows fix: bump renovate job to Node 24, [email protected] requires it 2026-09-11 18:03:48 -05:00
README.md Derive repository from github context, drop with: inputs 2026-09-06 16:48:38 -05:00

forgejo-workflows

Shared, reusable Forgejo Actions workflows for colibrisec repos. One copy to maintain instead of one per repo.

Must stay public — Forgejo doesn't support calling reusable workflows from a private repository.

Neither workflow below takes a with: input. A reusable workflow runs with the calling repo's own github context, so github.repository is already owner/name for whichever repo called it — there's nothing for a caller to fill in (or get wrong).

security-scan

Runs ojo-forgejo and uploads findings to Balam via balam-forgejo, under the calling repo's own name.

name: security-scan

on:
  push:
    branches: [main]
  pull_request:

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  scan:
    uses: colibrisec/forgejo-workflows/.forgejo/workflows/security-scan.yml@<commit-sha>
    secrets:
      BALAM_URL: ${{ secrets.BALAM_URL }}
      BALAM_TOKEN: ${{ secrets.BALAM_TOKEN }}

Requires BALAM_URL and BALAM_TOKEN secrets on the calling repo.

renovate

Runs Renovate against the calling repo, pointed at this Forgejo instance.

name: renovate

on:
  schedule:
    - cron: '0 4 * * *'
  workflow_dispatch:

jobs:
  renovate:
    uses: colibrisec/forgejo-workflows/.forgejo/workflows/renovate.yml@<commit-sha>
    secrets:
      RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}

Requires a RENOVATE_TOKEN secret on the calling repo (a personal API token, ideally for a bot account scoped only to repos it needs to manage).

Versioning

Callers pin to a commit SHA, not @main — a reusable-workflow call runs with access to whatever secrets the caller passes it, so a mutable ref would let a future push here silently change what every caller executes. Bump a caller's pin by hand when this repo changes and the caller wants the update.

If a change here needs to break an existing workflow's inputs, cut a new workflow file rather than changing one out from under every caller still pinned to an older commit.