From 163205b4000ccd026e372bad45783de3ebfe1c35 Mon Sep 17 00:00:00 2001 From: tyler Date: Mon, 18 Sep 2023 20:59:42 +0000 Subject: [PATCH 1/3] Fix error when removing nonexistent artifact --- .github/workflows/build.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 36662694..fcee0799 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -246,7 +246,7 @@ jobs: - name: Prepare artifacts output directory run: | mkdir -p $(dirname $ARTIFACTS_PATH) - rm "$ARTIFACTS_PATH" + rm -f "$ARTIFACTS_PATH" - name: Build CLI id: build run: task build-cli From fbdf402af5779f8e0f5454b445695d998df32aae Mon Sep 17 00:00:00 2001 From: tyler Date: Mon, 18 Sep 2023 21:09:54 +0000 Subject: [PATCH 2/3] Debugging event name context variable --- .github/workflows/code-scanning.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/code-scanning.yml b/.github/workflows/code-scanning.yml index 91794f72..4badfde4 100644 --- a/.github/workflows/code-scanning.yml +++ b/.github/workflows/code-scanning.yml @@ -14,6 +14,7 @@ jobs: dependency-review: name: Dependency Review runs-on: ubuntu-latest + # if: github.event_name == steps: - uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09 # v2.5.1 with: @@ -26,6 +27,9 @@ jobs: with: show-progress: 'false' persist-credentials: 'false' + - run: echo "$DEBUG_EVENT_NAME" + env: + DEBUG_EVENT_NAME: ${{ github.event_name }} - uses: actions/dependency-review-action@v3 codeql: From 945ba489c85a15bec65c25681f53a54cd15396f3 Mon Sep 17 00:00:00 2001 From: tyler Date: Mon, 18 Sep 2023 21:11:42 +0000 Subject: [PATCH 3/3] Limit "Dependency Review" job to PRs --- .github/workflows/code-scanning.yml | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.github/workflows/code-scanning.yml b/.github/workflows/code-scanning.yml index 4badfde4..6fd7aed5 100644 --- a/.github/workflows/code-scanning.yml +++ b/.github/workflows/code-scanning.yml @@ -14,7 +14,7 @@ jobs: dependency-review: name: Dependency Review runs-on: ubuntu-latest - # if: github.event_name == + if: github.event_name == 'pull_request' steps: - uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09 # v2.5.1 with: @@ -27,9 +27,6 @@ jobs: with: show-progress: 'false' persist-credentials: 'false' - - run: echo "$DEBUG_EVENT_NAME" - env: - DEBUG_EVENT_NAME: ${{ github.event_name }} - uses: actions/dependency-review-action@v3 codeql: