fix: correct security-scan.yml reusable-workflow call #15

Merged
james merged 1 commit from fix/security-scan-input into main 2026-09-06 21:55:55 +00:00
Owner

Same fix as colibrisec/balam#13 and colibrisec/balam-forgejo#6 � security-scan.yml was passing with: repository: colibrisec/ojo-forgejo (wrong key, and coincidentally the right value here only because this happens to be that repo). Depends on colibrisec/forgejo-workflows#3, which drops the input entirely, so this also removes the now-unnecessary with: block from both workflows and switches secrets: inherit to explicit mapping.

Same fix as colibrisec/balam#13 and colibrisec/balam-forgejo#6 � `security-scan.yml` was passing `with: repository: colibrisec/ojo-forgejo` (wrong key, and coincidentally the right value here only because this happens to be that repo). Depends on colibrisec/forgejo-workflows#3, which drops the input entirely, so this also removes the now-unnecessary `with:` block from both workflows and switches `secrets: inherit` to explicit mapping.
fix: use simplified input-free reusable workflows, correct SHA pin
All checks were successful
test / test (pull_request) Successful in 25s
security-scan / scan-1 (pull_request) Successful in 1m7s
security-scan / scan (pull_request) Successful in 0s
4cdf594c59
Supersedes the earlier product-name/repository input-based version: the
shared workflows (colibrisec/forgejo-workflows) now derive the calling
repo's name from github.repository internally, so callers need nothing
but uses: + secrets:.
james merged commit 8ef7c5da71 into main 2026-09-06 21:55:55 +00:00
james deleted branch fix/security-scan-input 2026-09-06 21:55:56 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/ojo-forgejo!15
No description provided.