Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
2127 commits
Select commit Hold shift + click to select a range
ba9d378
Changing default behavior to include comment summary in PR
jonjanego Feb 6, 2024
8aab15d
Update code-scanning/dependency-review.yml
jonjanego Feb 7, 2024
c4f5db6
Code Scanning shouldn't own `dependency-review.yml`
sampart Feb 7, 2024
da7a61e
Merge pull request #2297 from actions/jonjanego-patch-1
jonjanego Feb 7, 2024
813dc76
Merge branch 'main' into dependency-review-ownership
sampart Feb 9, 2024
2b5d980
Merge pull request #2299 from actions/dependency-review-ownership
sampart Feb 9, 2024
f263f7e
Run ci/rubyonrails with bundle exec
jamiemccarthy Feb 12, 2024
e4840c4
Spell bundle-audit without the r
jamiemccarthy Feb 12, 2024
4b8ca42
Prefer ruby/setup-ruby@v1
jamiemccarthy Feb 12, 2024
d303234
Update for `gradle/actions@v3.1.0` release
bigdaz Feb 13, 2024
be55258
Merge pull request #2305 from bigdaz/main
jonjanego Feb 14, 2024
05e4581
Update codeql.yml with new build-mode
marcogario Feb 15, 2024
8a97398
Update code-scanning/codeql.yml
marcogario Feb 19, 2024
4a8c4e0
Update code-scanning/codeql.yml
marcogario Feb 19, 2024
f2c131e
Merge branch 'main' into jm-ci-rubyonrails
jamiemccarthy Mar 2, 2024
0327789
tfsec latest v0.1.4 (#2318)
felickz Mar 6, 2024
3fb9f82
Updating dotnet CI starter workflows (#2333)
timheuer Mar 12, 2024
469c22e
ci/python-publish: bump, use trusted publishing
woodruffw Mar 19, 2024
f4c64fb
Apply suggestions from code review
woodruffw Mar 19, 2024
231e6b5
python-publish: contents: read at toplevel
woodruffw Mar 19, 2024
e230215
python-publish: explanatory comment
woodruffw Mar 19, 2024
1fa8e18
python-publish: copy gem-push.yml's pattern
woodruffw Mar 19, 2024
e44c7b5
python-publish: environment
woodruffw Mar 19, 2024
0f4d223
Update astro.yml for yarn based project
cclinet Mar 25, 2024
61cdce2
Updating nextjs.yml for Next.js 14 Support (#2204)
NPJigaK Mar 25, 2024
aad9272
Update codeql.yml
marcogario Mar 26, 2024
97c6254
Merge branch 'main' into update_codeql_template
marcogario Mar 26, 2024
fdbad9c
Update codeql.yml
marcogario Mar 26, 2024
4ccc742
Merge pull request #2306 from actions/update_codeql_template
marcogario Mar 26, 2024
831e9cb
Bump workflow actions of various starter files (#2210)
deining Mar 27, 2024
4620c76
update Scorecard Action hashes and version comments (#2348)
spencerschrock Mar 27, 2024
0ac8e61
Merge branch 'main' into update-astro-for-yarn
JamesMGreene Mar 28, 2024
539cde5
Merge pull request #2351 from cclinet/update-astro-for-yarn
JamesMGreene Mar 28, 2024
4ca845b
Update CODEOWNERS
alexisabril Mar 29, 2024
87efe4c
Update CODEOWNERS
alexisabril Mar 29, 2024
e6175cb
Merge pull request #2359 from actions/alexisabril-patch-1
cdb Mar 29, 2024
c9a0122
Update all Pages workflows to use actions/configure-pages@v5
JamesMGreene Mar 30, 2024
eeef7a7
Merge pull request #2360 from actions/configure-pages-v5
JamesMGreene Mar 30, 2024
e4837fa
Improve step name for Next.js build
JamesMGreene Mar 30, 2024
efd31e5
update soos dash action commit hash / sarif action version / logo (#2…
SOOS-GSteen Apr 1, 2024
b53d05e
ci: use artisan command to run test, because this ci/laravel.yml does…
cgarciagarcia Apr 1, 2024
31a3e00
codeql: Clarify that hosted larger runners only exist on GHEC
issyl0 Apr 3, 2024
607f368
Merge pull request #2363 from actions/larger-runners-not-ghes
issyl0 Apr 3, 2024
cd4b67d
Checkout: Update all workflows to use Checkout V4
jsoref Jan 3, 2024
ca5bcdc
Add OSV-Scanner code scanning workflow (#2350)
another-rex Apr 10, 2024
a3194f5
Update CodeQL workflow to use packages:read permission.
marcogario Apr 11, 2024
9963e8c
Merge pull request #2372 from actions/codeql-packages-read
marcogario Apr 11, 2024
ac9c407
Add starter-workflows for Policy Validator (#2375)
mponaws Apr 18, 2024
7e9ab60
remove pages for now
tsusdere Apr 19, 2024
29b0a3e
Update settings.json
tsusdere Apr 19, 2024
8ff5c7e
Merge branch 'main' into bump-actions
DanRigby Apr 25, 2024
2435e57
Merge pull request #2270 from jsoref/bump-actions
DanRigby Apr 25, 2024
b81d5bf
Bump actions/cache from 3 to 4
dependabot[bot] Apr 25, 2024
37d6de7
Setup-Java: Update all workflows to use Setup-Java V4
jsoref Apr 25, 2024
545832a
Setup-Dotnet: Update all workflows to Setup-Dotnet V4
jsoref Apr 25, 2024
d51dfab
Artifacts: Update all workflows to use Artifacts V4
jsoref Apr 25, 2024
a072fdf
Labeler: Update to v5
jsoref Apr 25, 2024
1830845
Setup-Node: Update all workflows to use Setup-Node V4
jsoref Apr 25, 2024
23a568e
fix(openshift): comment out dangling dependency
jsoref Apr 26, 2024
64be628
Merge branch 'main' into jm-ci-rubyonrails
jamiemccarthy Apr 26, 2024
e656ded
Reference ruby/setup-ruby with latest commit hash
jamiemccarthy Apr 26, 2024
93f1d5f
Merge branch 'main' into ww/trusted-publish
woodruffw Apr 28, 2024
5902ad7
Update script/sync-ghes/settings.json
yoannchaudet Apr 29, 2024
d526113
Update script/sync-ghes/settings.json
yoannchaudet Apr 29, 2024
7d07997
Update script/sync-ghes/settings.json
yoannchaudet Apr 29, 2024
15066a3
Merge branch 'main' into tsusdere-patch-1
yoannchaudet Apr 29, 2024
79af930
Merge pull request #2376 from actions/tsusdere-patch-1
yoannchaudet Apr 29, 2024
2649624
ici
yoannchaudet Apr 29, 2024
c748053
again
yoannchaudet Apr 29, 2024
252e935
ghes
yoannchaudet Apr 29, 2024
1e15901
wip
yoannchaudet Apr 29, 2024
138375b
wip
yoannchaudet Apr 29, 2024
66e7ed4
wip
yoannchaudet Apr 29, 2024
ddca0a9
async
yoannchaudet Apr 29, 2024
3fa8d36
async
yoannchaudet Apr 29, 2024
9f6e4a9
wip
yoannchaudet Apr 29, 2024
0073136
wip
yoannchaudet Apr 29, 2024
dd92d37
wip
yoannchaudet Apr 29, 2024
2c3a9ca
Update script/sync-ghes/index.ts
yoannchaudet Apr 29, 2024
9b485d4
Merge pull request #2388 from actions/readonly-sync
yoannchaudet Apr 29, 2024
b30fbdf
Specify bash shell so that it doesn't fail if switching to 'windows`
felickz May 2, 2024
6702f0d
Fortify Starter Workflow to use new Fortify AST Action (#2245)
dylanbthomas May 6, 2024
899b09b
Merge branch 'main' into patch-5
marcogario May 13, 2024
e83edef
Merge pull request #2392 from felickz/patch-5
marcogario May 13, 2024
841e9af
Merge branch 'main' into ww/trusted-publish
woodruffw May 13, 2024
7ea2dd7
Update Mayhem for API to reference new site
Ross-ForAllSecure May 21, 2024
3913143
Fix typo in grade starter workflow
cory-miller May 22, 2024
7ce8d32
Merge pull request #2403 from cory-miller/main
konradpabjan May 23, 2024
61d42c9
Update cosign versions
jhutchings1 May 30, 2024
c2f413d
Merge pull request #2414 from actions/docker-patch
felipesu19 May 30, 2024
de925c9
Frogbot: Update to 2.21.0
yahavi Jun 1, 2024
f308bd9
Merge branch 'main' into jm-ci-rubyonrails
jamiemccarthy Jun 2, 2024
74366ef
Update DataDog/synthetics-ci-github-action workflow
AntoineDona Jun 3, 2024
9f1db53
Update sonarcloud.yml after latest release of the action (#2405)
antoine-vinot-sonarsource Jun 3, 2024
5c09eb8
Merge branch 'main' into datadog-update
AntoineDona Jun 4, 2024
a0f4ad0
Merge branch 'main' into jm-ci-rubyonrails
jamiemccarthy Jun 8, 2024
5a11e59
Reference latest ruby/setup-ruby (1.179.1) with commit hash
jamiemccarthy Jun 8, 2024
0321f5f
Run lint with binstubs
jamiemccarthy Jun 8, 2024
ca01025
Merge branch 'main' into ww/trusted-publish
woodruffw Jun 13, 2024
647cac4
Update policy validator starter workflows (#2433)
alankuo-aws Jun 17, 2024
87834aa
Merge branch 'main' into ww/trusted-publish
woodruffw Jun 21, 2024
dc63c58
Update for gradle/actions@v3.4.2 release
cdsap Jun 21, 2024
856c9e2
Merge branch 'main' into datadog-update
AntoineDona Jun 24, 2024
a2d9dce
Merge branch 'main' into bump-frogbot
yahavi Jun 28, 2024
eb0381d
Update to 2.21.2
yahavi Jun 28, 2024
4655579
Fix wrong hash
AntoineDona Jun 28, 2024
e6a8487
pages: Update Hugo workflow
jmooring Jun 28, 2024
889ae22
Merge pull request #2442 from jmooring/update-hugo-workflow
yoannchaudet Jul 2, 2024
b92a38f
Merge branch 'main' into datadog-update
AntoineDona Jul 11, 2024
763a1a6
Upload-Sarif: Update all workflows to use Upload-Sarif V3
jsoref Apr 25, 2024
9be7944
Merge branch 'main' into bump-actions-load-artifact
thyeggman Jul 29, 2024
309e783
Merge branch 'main' into bump-actions-setup-dotnet
thyeggman Jul 29, 2024
bb5f99b
Merge branch 'main' into bump-actions-setup-java
thyeggman Jul 29, 2024
04bebdd
Merge branch 'main' into bump-actions-setup-node
thyeggman Jul 29, 2024
570cd92
Switch github upload sarif to tag
jsoref Jul 29, 2024
cf76f82
Merge pull request #2383 from jsoref/bump-actions-load-artifact
thyeggman Jul 30, 2024
47f69d7
Revert "Artifacts: Update all workflows to use Artifacts V4"
thyeggman Jul 30, 2024
fe6ffc7
Merge branch 'main' into bump-actions-setup-dotnet
thyeggman Jul 30, 2024
3eb748f
Merge pull request #2458 from actions/revert-2383-bump-actions-load-a…
thyeggman Jul 30, 2024
a256a78
Merge branch 'main' into bump-actions-setup-dotnet
thyeggman Jul 30, 2024
27da85b
Merge pull request #2382 from jsoref/bump-actions-setup-dotnet
thyeggman Jul 30, 2024
7be9afd
Merge branch 'main' into bump-actions-setup-java
thyeggman Jul 30, 2024
137b5a7
Merge pull request #2381 from jsoref/bump-actions-setup-java
thyeggman Jul 30, 2024
1e293ee
Merge branch 'main' into bump-actions-setup-node
thyeggman Jul 30, 2024
9598b1c
Merge pull request #2380 from jsoref/bump-actions-setup-node
thyeggman Jul 30, 2024
e1c2a47
Merge branch 'main' into bump-actions-upload-sarif
thyeggman Jul 30, 2024
c46165a
Merge pull request #2379 from jsoref/bump-actions-upload-sarif
thyeggman Jul 30, 2024
aa685e1
Merge branch 'main' into bump-frogbot
thyeggman Jul 31, 2024
917cb9d
Merge pull request #2420 from yahavi/bump-frogbot
thyeggman Aug 1, 2024
d7fb74c
Merge branch 'main' into main
thyeggman Aug 1, 2024
9dc81a3
Merge pull request #2439 from cdsap/main
thyeggman Aug 1, 2024
a7ba2ca
Merge branch 'main' into jm-ci-rubyonrails-binstubs
thyeggman Aug 1, 2024
ee5db07
Merge pull request #2427 from jamiemccarthy/jm-ci-rubyonrails-binstubs
thyeggman Aug 1, 2024
b5d5fd9
Merge branch 'main' into datadog-update
thyeggman Aug 1, 2024
c7c1192
Merge pull request #2424 from AntoineDona/datadog-update
thyeggman Aug 1, 2024
81a51b8
Merge branch 'main' into main
thyeggman Aug 1, 2024
dfcb7f5
Merge branch 'main' into issue-2385
thyeggman Aug 1, 2024
2918f7d
Merge pull request #2386 from jsoref/issue-2385
thyeggman Aug 1, 2024
881de4b
Merge branch 'main' into bump-actions-labeler
thyeggman Aug 1, 2024
7fc34f2
Merge pull request #2384 from jsoref/bump-actions-labeler
thyeggman Aug 1, 2024
4f23ad3
Merge branch 'main' into main
thyeggman Aug 1, 2024
a44a949
Update labeler.yml for v5
thyeggman Aug 1, 2024
5eed24d
Merge pull request #2402 from Ross-ForAllSecure/main
thyeggman Aug 1, 2024
e5c27e8
Merge branch 'main' into thyeggman-patch-1
thyeggman Aug 1, 2024
6707b74
Merge pull request #2460 from actions/thyeggman-patch-1
thyeggman Aug 1, 2024
9512b1a
Update stale.yml to only use workflow_dispatch
thyeggman Aug 1, 2024
5241fd1
Merge pull request #2461 from actions/thyeggman-patch-1
thyeggman Aug 1, 2024
a504754
Ubuntu-Latest: Update all workflows to use ubuntu-latest
jsoref Aug 6, 2024
fdb3717
Update for `gradle/actions@v4.0.0` release
bigdaz Aug 7, 2024
f81606b
Merge pull request #2468 from bigdaz/main
elbrenn Aug 12, 2024
af1bbdc
Update soos-dast-scan.yml hash (#2466)
SOOS-GSteen Aug 16, 2024
83b6e98
Add Debricked starter workflow (#2107)
4ernovm Aug 16, 2024
5ad4947
Update ci/python-publish.yml
woodruffw Aug 16, 2024
e5a2609
Merge branch 'main' into ww/trusted-publish
woodruffw Aug 16, 2024
ba12583
CodeQL: Remove Swift 2h timeout
igfoo Aug 20, 2024
91fe144
Merge pull request #2479 from igfoo/igfoo/swift_timeout
orhantoy Aug 20, 2024
26ad7a7
Update ci/python-publish.yml
woodruffw Aug 20, 2024
ae01bb2
google: update workflow versions and instructions (#2478)
sethvargo Aug 21, 2024
6ac176a
CodeQL - Add unique name vs default setup
felickz Aug 23, 2024
9fccc75
Merge pull request #2482 from felickz/patch-5
marcogario Sep 3, 2024
09465a4
Merge branch 'main' into ww/trusted-publish
woodruffw Sep 4, 2024
bc709b6
python-publish: bump commit/ref
woodruffw Sep 4, 2024
9db23a2
Add Appknox starter workflow (#2447)
ginilpg Sep 10, 2024
53980cb
Update eslint.yml
aeisenberg Sep 10, 2024
ddb47be
Update appknox.yml
aeisenberg Sep 10, 2024
9d2ae7c
Update appknox.yml
aeisenberg Sep 10, 2024
dea60ba
Update code-scanning/eslint.yml
aeisenberg Sep 11, 2024
8190cec
Merge pull request #2496 from aeisenberg/patch-2
cannist Sep 12, 2024
666350e
Added appknox.yml for code scanning (#2498)
ginilpg Sep 17, 2024
09fa3b9
add jfrog-sast flow
ilya-k-1 Oct 21, 2024
7f50c70
pass token over stdin, add security to properties
ilya-k-1 Oct 22, 2024
1394e47
Merge pull request #2559 from ilya-k-1/jfrog/add_jfrog_sast_flow
orhantoy Oct 22, 2024
958eb20
Update ci/python-publish.yml
woodruffw Nov 5, 2024
66c4bdd
Merge branch 'main' into ww/trusted-publish
woodruffw Nov 5, 2024
3477847
Update ci/python-publish.yml
woodruffw Nov 6, 2024
eb32979
Update ci/python-publish.yml
woodruffw Nov 7, 2024
4cbe535
Update Fortify starter workflow
rsenden Nov 6, 2024
1969736
Remove trailing spaces
rsenden Nov 8, 2024
1c6c18c
Remove trailing spaces
rsenden Nov 8, 2024
0486897
Update action version, update comment
rsenden Nov 22, 2024
eee067e
Apply suggestions from code review
woodruffw Nov 22, 2024
00795b7
Apply suggestions from code review
woodruffw Nov 22, 2024
dfc0cdc
Merge pull request #2345 from trail-of-forks/ww/trusted-publish
elbrenn Nov 22, 2024
f90b59f
Add Octopus Deploy release and deploy workflow (#2651)
zentron Dec 13, 2024
1cc1562
Added Black-Duck-Security-Scan logo
sadmananik Dec 18, 2024
4a84ccf
Added black duck security scan action template
sadmananik Dec 18, 2024
1c8781f
Merge pull request #1 from blackduck-inc/blackducksecurityscan-template
sadmananik Dec 18, 2024
84747ed
Used hash instead of tag name
sadmananik Dec 23, 2024
9e76f84
Merge pull request #2 from blackduck-inc/blackducksecurityscan-template
sadmananik Dec 23, 2024
9351ace
Remove trailing whitespace
jsoref Jan 6, 2025
17f0d24
Use unix line endings
jsoref Jan 6, 2025
d9c5f62
Fix sentence style
jsoref Jan 6, 2025
be1cddb
Checkout: Update all workflows to use Checkout V4
jsoref Aug 6, 2024
e1deb63
Merge branch 'main' into ubuntu-latest
elbrenn Jan 13, 2025
a38d8ca
Merge pull request #2464 from jsoref/ubuntu-latest
elbrenn Jan 13, 2025
016b907
Merge branch 'main' into fix-octopus-deploy
elbrenn Jan 13, 2025
f4f8d50
Merge pull request #2711 from jsoref/fix-octopus-deploy
elbrenn Jan 13, 2025
f8ea592
Update jekyll.yml
tsusdere Jan 13, 2025
b001911
Merge pull request #2720 from actions/update-ruby
tsusdere Jan 13, 2025
95a3224
Remove stray `-`
jsoref Jan 14, 2025
3cd0650
Merge branch 'main' into bump-actions
elbrenn Jan 14, 2025
f480e98
Merge pull request #2465 from jsoref/bump-actions
elbrenn Jan 14, 2025
c8284a4
Update debricked.yml
sweoggy Sep 12, 2024
1e05f3c
Update starter workflows to use the latest artifact actions (#2726)
joshmgross Jan 21, 2025
9085976
SOOS Dast Feature Update (#2733)
SOOS-GSteen Jan 24, 2025
56844b1
Merge branch 'main' into main
sadmananik Jan 28, 2025
2abfcee
Update codeql.yml
aeisenberg Jan 29, 2025
7398b4e
Remove trailing whitespace
aeisenberg Jan 29, 2025
1de3a14
Update black-duck-security-scan-ci.yml
sadmananik Jan 30, 2025
adcb922
Make the example setup more explicit.
aeisenberg Jan 31, 2025
55eb185
Merge pull request #2748 from aeisenberg/patch-3
orhantoy Feb 3, 2025
7db0075
Code Scanning: bandit to latest hash
felickz Feb 3, 2025
51a27e7
Merge branch 'main' into main
sadmananik Feb 4, 2025
5969feb
Resolved reviwed comments
sadmananik Feb 5, 2025
345594d
Updated actions/checkout v3 to v4
sadmananik Feb 7, 2025
fcdc128
Fixed Linting Issues
sadmananik Feb 10, 2025
a00915e
Merge pull request #2676 from blackduck-inc/main
AlexDeMichieli Feb 10, 2025
f70f9c8
bump action versions to latest to resolve issues
spencerschrock Feb 24, 2025
41e00af
Limit scorecard to default branch
jsoref Feb 4, 2025
4a5b493
add future looking pull_request event to conditional
spencerschrock Feb 24, 2025
c95135c
Merge branch 'main' into patch-5
felickz Mar 5, 2025
a413869
Merge pull request #2759 from felickz/patch-5
marcogario Mar 5, 2025
dd84e34
Update to latest published action version
rsenden Mar 17, 2025
7525cf0
Merge branch 'main' into fortify-20241106
rsenden Mar 17, 2025
17ba94a
Merge pull request #2588 from fortify/fortify-20241106
yacaovsnc Mar 24, 2025
0d93bc2
Merge branch 'main' into scorecard-bug-fix
konradpabjan Mar 25, 2025
85c6b7a
Merge pull request #2786 from spencerschrock/scorecard-bug-fix
konradpabjan Mar 25, 2025
bd28c76
Merge branch 'main' into dependabot/github_actions/actions/cache-4
AnthonyZavala Apr 22, 2025
9c3c789
Merge pull request #2369 from actions/dependabot/github_actions/actio…
AnthonyZavala Apr 22, 2025
a041377
Add summary preview workflow
sgoedecke Apr 22, 2025
f0c24a6
Sentence case step names
sgoedecke Apr 22, 2025
f1f24bd
Remove newline
sgoedecke Apr 22, 2025
17b8575
Use latest version of checkout, add permission for checkout, and use …
sgoedecke Apr 22, 2025
5e895b8
Merge branch 'main' into sgoedecke/add-new-preview-workflow
sgoedecke Apr 23, 2025
e101f44
Merge pull request #2847 from sgoedecke/sgoedecke/add-new-preview-wor…
AnthonyZavala Apr 23, 2025
736803b
Remove preview label from summary.properties.json
sgoedecke Apr 24, 2025
43366bb
Merge pull request #2851 from sgoedecke/patch-1
AnthonyZavala Apr 24, 2025
84e227a
Update README.md
nebuk89 Jun 6, 2025
58e7cd0
Merge pull request #2900 from actions/nebuk89-patch-1
elbrenn Jun 6, 2025
69b278a
Update CodeQL action versions to v4 in workflow configuration
mario-campos Oct 7, 2025
43f0e19
Add `name` to manual build step in CodeQL starter workflow
mario-campos Oct 9, 2025
d3334c0
Merge pull request #3082 from mario-campos/mario-campos/codeql-action-v4
cannist Oct 15, 2025
ab2a8c2
Merge branch 'actions:main' into main
nagarjunsanji Dec 1, 2025
6c9f4c4
Merge pull request #2499 from debricked/main
cannist Dec 1, 2025
c6f662d
Removing gulp as legacy and no longer required
nebuk89 Dec 4, 2025
41f167b
Removing grunt as outdated
nebuk89 Dec 4, 2025
afb9bf3
Merge pull request #3122 from nebuk89/nebuk89-tmp
thboop Dec 4, 2025
0819b4d
Create deno.yml
mohamedsaid7720077-collab Feb 3, 2026
d51a545
Add settings for GitHub Copilot chat search view results
mohamedsaid7720077-collab Mar 19, 2026
e40034b
d51a54516ec5d42cff037cf1415407a0a795351e
mohamedsaid7720077-collab Mar 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
17 changes: 17 additions & 0 deletions .github/auto_assign.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Set to true to add reviewers to pull requests
addReviewers: true

# Set to true to add assignees to pull requests
addAssignees: false

# A list of reviewers to be added to pull requests (GitHub user name)
reviewers:
- phantsure
- anuragc617
- tiwarishub
- vsvipul
- bishal-pdmsft

# A number of reviewers added to the pull request
# Set 0 to add all the reviewers (default: 0)
numberOfReviewers: 1
16 changes: 16 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates

version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"

- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
4 changes: 4 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Add 'code-scanning' label to any changes within 'code-scanning' folder or any subfolders
code-scanning:
- changed-files:
- any-glob-to-any-file: code-scanning/**/*
64 changes: 47 additions & 17 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,31 +1,61 @@
Thank you for sending in this pull request. Please make sure you take a look at the [contributing file](https://github.com/actions/starter-workflows/blob/master/CONTRIBUTING.md). Here's a few things for you to consider in this pull request:
<!--
IMPORTANT:

- [ ] Include a good description of the workflow.
- [ ] Links to the language or tool will be nice (unless its really obvious)
This repository contains configuration for what users see when they click on the `Actions` tab and the setup page for Code Scanning.

In the workflow and properties files:
It is not:
* A playground to try out scripts
* A place for you to create a workflow for your repository
-->

- [ ] The workflow filename of CI workflows should be the name of the language or platform, in lower case. Special characters should be removed or replaced with words as appropriate (for example, "dotnet" instead of ".NET").
## Pre-requisites

The workflow filename of publishing workflows should be the name of the language or platform, in lower case, followed by "-publish".
- [ ] Includes a matching `ci/properties/*.properties.json` file.
- [ ] Use sentence case for the names of workflows and steps, for example "Run tests".
- [ ] The name of CI workflows should only be the name of the language or platform: for example "Go" (not "Go CI" or "Go Build")
- [ ] Include comments in the workflow for any parts that are not obvious or could use clarification.
- [ ] CI workflows should run on `push` to `branches: [ master ]` and `pull_request` to `branches: [ master ]`.
- [ ] Prior to submitting a new workflow, please apply to join the GitHub Technology Partner Program: [partner.github.com/apply](https://partner.github.com/apply?partnershipType=Technology+Partner).

Packaging workflows should run on `release` with `types: [ created ]`.
---

Some general notes:
### **Please note that at this time we are only accepting new starter workflows for Code Scanning. Updates to existing starter workflows are fine.**

- [ ] This workflow must only use actions that are produced by GitHub, [in the `actions` organization](https://github.com/actions), **or**
---

This workflow must only use actions that are produced by the language or ecosystem that the workflow supports. These actions must be [published to the GitHub Marketplace](https://github.com/marketplace?type=actions). Workflows using these actions must reference the action using the full 40 character hash of the action's commit instead of a tag. Additionally, workflows must include the following comment at the top of the workflow file:
## Tasks

**For _all_ workflows, the workflow:**

- [ ] Should be contained in a `.yml` file with the language or platform as its filename, in lower, [_kebab-cased_](https://en.wikipedia.org/wiki/Kebab_case) format (for example, [`docker-image.yml`](https://github.com/actions/starter-workflows/blob/main/ci/docker-image.yml)). Special characters should be removed or replaced with words as appropriate (for example, "dotnet" instead of ".NET").
- [ ] Should use sentence case for the names of workflows and steps (for example, "Run tests").
- [ ] Should be named _only_ by the name of the language or platform (for example, "Go", not "Go CI" or "Go Build").
- [ ] Should include comments in the workflow for any parts that are not obvious or could use clarification.
- [ ] Should specify least privileged [permissions](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token) for `GITHUB_TOKEN` so that the workflow runs successfully.

**For _CI_ workflows, the workflow:**

- [ ] Should be preserved under [the `ci` directory](https://github.com/actions/starter-workflows/tree/main/ci).
- [ ] Should include a matching `ci/properties/*.properties.json` file (for example, [`ci/properties/docker-publish.properties.json`](https://github.com/actions/starter-workflows/blob/main/ci/properties/docker-publish.properties.json)).
- [ ] Should run on `push` to `branches: [ $default-branch ]` and `pull_request` to `branches: [ $default-branch ]`.
- [ ] Packaging workflows should run on `release` with `types: [ created ]`.
- [ ] Publishing workflows should have a filename that is the name of the language or platform, in lower case, followed by "-publish" (for example, [`docker-publish.yml`](https://github.com/actions/starter-workflows/blob/main/ci/docker-publish.yml)).

**For _Code Scanning_ workflows, the workflow:**

- [ ] Should be preserved under [the `code-scanning` directory](https://github.com/actions/starter-workflows/tree/main/code-scanning).
- [ ] Should include a matching `code-scanning/properties/*.properties.json` file (for example, [`code-scanning/properties/codeql.properties.json`](https://github.com/actions/starter-workflows/blob/main/code-scanning/properties/codeql.properties.json)), with properties set as follows:
- [ ] `name`: Name of the Code Scanning integration.
- [ ] `creator`: Name of the organization/user producing the Code Scanning integration.
- [ ] `description`: Short description of the Code Scanning integration.
- [ ] `categories`: Array of languages supported by the Code Scanning integration.
- [ ] `iconName`: Name of the SVG logo representing the Code Scanning integration. This SVG logo must be present in [the `icons` directory](https://github.com/actions/starter-workflows/tree/main/icons).
- [ ] Should run on `push` to `branches: [ $default-branch, $protected-branches ]` and `pull_request` to `branches: [ $default-branch ]`. We also recommend a `schedule` trigger of `cron: $cron-weekly` (for example, [`codeql.yml`](https://github.com/actions/starter-workflows/blob/c59b62dee0eae1f9f368b7011cf05c2fc42cf084/code-scanning/codeql.yml#L14-L21)).

**Some general notes:**

- [ ] This workflow must _only_ use actions that are produced by GitHub, [in the `actions` organization](https://github.com/actions), **or**
- [ ] This workflow must _only_ use actions that are produced by the language or ecosystem that the workflow supports. These actions must be [published to the GitHub Marketplace](https://github.com/marketplace?type=actions). We require that these actions be referenced using the full 40 character hash of the action's commit instead of a tag. Additionally, workflows must include the following comment at the top of the workflow file:
```
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.
```
- [ ] This workflow must not send data to any 3rd party service except for the purposes of installing dependencies.
- [ ] This workflow must not use a paid service or product.
- [ ] Automation and CI workflows should not send data to any 3rd party service except for the purposes of installing dependencies.
- [ ] Automation and CI workflows cannot be dependent on a paid service or product.
15 changes: 15 additions & 0 deletions .github/workflows/auto-assign-issues.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: Issue assignment

on:
issues:
types: [opened]

jobs:
auto-assign:
runs-on: ubuntu-latest
steps:
- name: 'Auto-assign issue'
uses: pozil/auto-assign-issue@v1.11.0
with:
assignees: phantsure,tiwarishub,anuragc617,vsvipul,bishal-pdmsft
numOfAssignee: 1
10 changes: 10 additions & 0 deletions .github/workflows/auto-assign.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
name: 'Auto Assign'
on:
pull_request_target:
types: [opened, ready_for_review]

jobs:
add-reviews:
runs-on: ubuntu-latest
steps:
- uses: kentaro-m/auto-assign-action@v1.2.2
42 changes: 42 additions & 0 deletions .github/workflows/deno.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.

# This workflow will install Deno then run `deno lint` and `deno test`.
# For more information see: https://github.com/denoland/setup-deno

name: Deno

on:
push:
branches: ["main"]
pull_request:
branches: ["main"]

permissions:
contents: read

jobs:
test:
runs-on: ubuntu-latest

steps:
- name: Setup repo
uses: actions/checkout@v4

- name: Setup Deno
# uses: denoland/setup-deno@v1
uses: denoland/setup-deno@61fe2df320078202e33d7d5ad347e7dcfa0e8f31 # v1.1.2
with:
deno-version: v1.x

# Uncomment this step to verify the use of 'deno fmt' on each commit.
# - name: Verify formatting
# run: deno fmt --check

- name: Run linter
run: deno lint

- name: Run tests
run: deno test -A
21 changes: 21 additions & 0 deletions .github/workflows/label-feature.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
name: Close as a feature
on:
issues:
types: [labeled]

jobs:
build:
permissions:
issues: write
runs-on: ubuntu-latest
steps:
- name: Close Issue
uses: peter-evans/close-issue@v3
if: contains(github.event.issue.labels.*.name, 'feature')
with:
comment: |
Thank you 🙇 for this request. This request has been classified as a feature by the maintainers.

We take all the requests for features seriously and have passed this on to the internal teams for their consideration.

Because any feature requires further maintenance and support in the long term by this team, we would like to exercise caution into adding new features. If this feature is something that can be implemented independently, please consider forking this repository and adding the feature.
21 changes: 21 additions & 0 deletions .github/workflows/label-support.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
name: Close as a support issue
on:
issues:
types: [labeled]

jobs:
build:
permissions:
issues: write
runs-on: ubuntu-latest
steps:
- name: Close Issue
uses: peter-evans/close-issue@v3
if: contains(github.event.issue.labels.*.name, 'support')
with:
comment: |
Sorry, but we'd like to keep issues related to code in this repository. Thank you 🙇

If you have questions about writing workflows or action files, then please [visit the GitHub Community Forum's Actions Board](https://github.community/t5/GitHub-Actions/bd-p/actions)

If you are having an issue or question about GitHub Actions then please [contact customer support](https://help.github.com/en/articles/about-github-actions#contacting-support)
16 changes: 16 additions & 0 deletions .github/workflows/labeler-triage.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
name: "Pull Request Labeler"

permissions:
contents: read
pull-requests: write

on:
pull_request_target:

jobs:
triage:
runs-on: ubuntu-latest
steps:
- uses: actions/labeler@v5
with:
repo-token: "${{ secrets.GITHUB_TOKEN }}"
31 changes: 31 additions & 0 deletions .github/workflows/lint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: Lint

on:
pull_request:
branches:
- main

jobs:

pre-commit:
name: pre-commit
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v4
with:
python-version: 3.11

- name: Cache pre-commit
uses: actions/cache@v4
with:
path: ~/.cache/pre-commit
key: pre-commit-3|${{ env.pythonLocation }}|${{ hashFiles('.pre-commit-config.yaml') }}

- name: Install pre-commit
run: pip3 install pre-commit

- name: Run pre-commit
run: pre-commit run --all-files --show-diff-on-failure --color always
23 changes: 23 additions & 0 deletions .github/workflows/stale.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: Mark stale issues and pull requests

on:
workflow_dispatch:
# schedule:
# - cron: "21 4 * * *"

jobs:
stale:

permissions:
issues: write
pull-requests: write
runs-on: ubuntu-latest

steps:
- uses: actions/stale@v8
with:
stale-issue-message: 'This issue has become stale and will be closed automatically within a period of time. Sorry about that.'
stale-pr-message: 'This pull request has become stale and will be closed automatically within a period of time. Sorry about that.'
stale-issue-label: 'no-issue-activity'
stale-pr-label: 'no-pr-activity'
days-before-stale: 90
Original file line number Diff line number Diff line change
@@ -1,26 +1,35 @@
name: Sync workflows for GHES

on:
push:
branches:
- master
branches: [ main ]

jobs:
sync:
permissions:
contents: write
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v4
- run: |
git fetch --no-tags --prune --depth=1 origin +refs/heads/*:refs/remotes/origin/*
git config user.email "cschleiden@github.com"
git config user.name "GitHub Actions"
- uses: actions/setup-node@v1
- uses: actions/setup-node@v4
with:
node-version: '12'
node-version: '20'
cache: 'npm'
cache-dependency-path: script/sync-ghes/package-lock.json
- name: Check starter workflows for GHES compat
run: |
npm ci
npx ts-node-script ./index.ts
working-directory: ./script/sync-ghes
- run: |
git add -A
git commit -m "Updating GHES workflows"
- run: git push
if [ -z "$(git status --porcelain)" ]; then
echo "No changes to commit"
else
git commit -m "Updating GHES workflows"
fi
- run: git push
25 changes: 25 additions & 0 deletions .github/workflows/validate-data.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: Validate Data

on:
push:
pull_request:

jobs:
validate-data:
permissions:
contents: read
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
cache-dependency-path: script/validate-data/package-lock.json

- name: Validate workflows
run: |
npm ci
npx ts-node-script ./index.ts
working-directory: ./script/validate-data
6 changes: 6 additions & 0 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
repos:
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.4.0
hooks:
- id: trailing-whitespace
files: (automation/|ci/|code-scanning/|deployments/|pages/).*(yaml|yml|json)$
6 changes: 6 additions & 0 deletions .vscode/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
{
"github.copilot.chat.getSearchViewResultsSkill.enabled": true,
"githubPullRequests.ignoredPullRequestBranches": [
"main"
]
}
5 changes: 5 additions & 0 deletions CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
* @actions/actions-workflow-development-reviewers @actions/starter-workflows

/code-scanning/ @actions/advanced-security-code-scanning @actions/actions-workflow-development-reviewers @actions/advanced-security-dependency-graph @actions/starter-workflows
/code-scanning/dependency-review.yml @actions/actions-workflow-development-reviewers @actions/advanced-security-dependency-graph @actions/starter-workflows
/pages/ @actions/pages @actions/actions-workflow-development-reviewers @actions/starter-workflows
Loading
Loading