| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
Some checks failed
ojo-scan.yml / Merge pull request 'fix: bump renovate job to Node 24, [email protected] requires it' (#5) from fix/renovate-node-version into main (push) Failing after 0s
renovate.yml / Merge pull request 'fix: bump renovate job to Node 24, [email protected] requires it' (#5) from fix/renovate-node-version into main (push) Failing after 0s
Reviewed-on: #5 |
||
| .forgejo/workflows | ||
| README.md | ||
forgejo-workflows
Shared, reusable Forgejo Actions workflows for colibrisec repos. One copy to maintain instead of one per repo.
Must stay public — Forgejo doesn't support calling reusable workflows from a private repository.
Neither workflow below takes a with: input. A reusable workflow runs with
the calling repo's own github context, so github.repository is already
owner/name for whichever repo called it — there's nothing for a caller to
fill in (or get wrong).
security-scan
Runs ojo-forgejo and uploads findings to Balam via balam-forgejo, under
the calling repo's own name.
name: security-scan
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
scan:
uses: colibrisec/forgejo-workflows/.forgejo/workflows/security-scan.yml@<commit-sha>
secrets:
BALAM_URL: ${{ secrets.BALAM_URL }}
BALAM_TOKEN: ${{ secrets.BALAM_TOKEN }}
Requires BALAM_URL and BALAM_TOKEN secrets on the calling repo.
renovate
Runs Renovate against the calling repo, pointed at this Forgejo instance.
name: renovate
on:
schedule:
- cron: '0 4 * * *'
workflow_dispatch:
jobs:
renovate:
uses: colibrisec/forgejo-workflows/.forgejo/workflows/renovate.yml@<commit-sha>
secrets:
RENOVATE_TOKEN: ${{ secrets.RENOVATE_TOKEN }}
Requires a RENOVATE_TOKEN secret on the calling repo (a personal API token,
ideally for a bot account scoped only to repos it needs to manage).
Versioning
Callers pin to a commit SHA, not @main — a reusable-workflow call runs with
access to whatever secrets the caller passes it, so a mutable ref would let a
future push here silently change what every caller executes. Bump a caller's
pin by hand when this repo changes and the caller wants the update.
If a change here needs to break an existing workflow's inputs, cut a new workflow file rather than changing one out from under every caller still pinned to an older commit.