Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 0 additions & 20 deletions .github/workflows/black.yml

This file was deleted.

23 changes: 23 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: CodeQL Code Scan

on:
push:
branches: [ "main" ]
schedule:
# Check every Monday at 04:36
- cron: "36 04 * * 1"

jobs:
codeql:
uses: mundialis/github-workflows/.github/workflows/codeql.yml@main

permissions:
# required for all workflows
security-events: write

# required to fetch internal or private CodeQL packs
packages: read

# only required for workflows in private repositories
actions: read
contents: read
4 changes: 4 additions & 0 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ on:
push:
branches:
- main

# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined:
permissions: {}

jobs:
deploy:
runs-on: ubuntu-latest
Expand Down
28 changes: 0 additions & 28 deletions .github/workflows/flake8.yml

This file was deleted.

24 changes: 24 additions & 0 deletions .github/workflows/linting.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
name: Linting and code quality check

on:
push:
branches:
- main
pull_request:
branches:
- main

jobs:
lint:
uses: mundialis/github-workflows/.github/workflows/linting.yml@main
with:
# exclude everything except flake8 and black
pylint-version: ''
ruff-version: ''
SUPER_LINTER_FILTER_REGEX_EXCLUDE: '.*'
# the workflow requires permissions that need to be granted by the parent job:
permissions:
contents: read
packages: read
# To report GitHub Actions status checks
statuses: write
3 changes: 3 additions & 0 deletions .github/workflows/python-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
release:
types: [published]

# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined:
permissions: {}

jobs:
publish-python:
uses: mundialis/github-workflows/.github/workflows/python-publish.yml@python-publish
Expand Down
21 changes: 21 additions & 0 deletions .github/workflows/sbom-vulnerability-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
name: SBOM Vulnerability Scan

on:
push:
branches: [ "main" ]
schedule:
# Check every Monday at 04:36
- cron: "36 04 * * 1"
release:
types: [published]


jobs:
sbom-scan:
permissions:
contents: read
security-events: write

uses: mundialis/github-workflows/.github/workflows/sbom-vulnerability-scan.yml@main
with:
pyproject: pyproject.toml
3 changes: 3 additions & 0 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ on:
# The branches below must be a subset of the branches above
branches: [ main ]

# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined:
permissions: {}

jobs:

integration-tests:
Expand Down
13 changes: 13 additions & 0 deletions .github/workflows/third-party-licenses.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
name: Generate Third-Party Licenses

on:
release:
types: [published]

permissions: {}

jobs:
generate-third-party-licenses:
uses: mundialis/github-workflows/.github/workflows/third-party-licenses.yml@main
with:
pyproject: pyproject.toml