This commit is contained in:
fkwp
2026-03-12 11:37:45 +01:00
parent 3e36891904
commit 4a2d8e8325
4 changed files with 6 additions and 6 deletions

View File

@@ -2,14 +2,14 @@ name: Prevent blocked
on: on:
# zizmor: ignore[dangerous-triggers] # zizmor: ignore[dangerous-triggers]
# Reason: This workflow does not checkout code or use secrets. # Reason: This workflow does not checkout code or use secrets.
# It only reads labels to set a failure status on the PR. # It only reads labels to set a failure status on the PR.
pull_request_target: pull_request_target:
types: [opened, labeled, unlabeled, synchronize] types: [opened, labeled, unlabeled, synchronize]
permissions: permissions:
pull-requests: read pull-requests: read
# Required to fail the check on the PR # Required to fail the check on the PR
statuses: write statuses: write
jobs: jobs:
prevent-blocked: prevent-blocked:

View File

@@ -8,7 +8,7 @@ on:
types: [labeled, unlabeled, opened] types: [labeled, unlabeled, opened]
permissions: permissions:
pull-requests: read pull-requests: read
statuses: write statuses: write
jobs: jobs:

View File

@@ -1,7 +1,7 @@
name: Deploy previews for PRs name: Deploy previews for PRs
on: on:
# zizmor: ignore[dangerous-triggers] # zizmor: ignore[dangerous-triggers]
# Reason: This is now restricted to internal PRs only using the 'if' condition below. # Reason: This is now restricted to internal PRs only using the 'if' condition below.
workflow_run: workflow_run:
workflows: ["Build"] workflows: ["Build"]
types: types:
@@ -16,7 +16,7 @@ jobs:
if: > if: >
github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.head_repository.full_name == github.repository github.event.workflow_run.head_repository.full_name == github.repository
runs-on: ubuntu-latest runs-on: ubuntu-latest
outputs: outputs:
pr_number: ${{ steps.prdetails.outputs.pr_id }} pr_number: ${{ steps.prdetails.outputs.pr_id }}

View File

@@ -22,7 +22,7 @@ jobs:
TAG: ${{ steps.tag.outputs.TAG }} TAG: ${{ steps.tag.outputs.TAG }}
steps: steps:
- name: Calculate VERSION - name: Calculate VERSION
# Safely store dynamic values in environment variables # Safely store dynamic values in environment variables
# to prevent shell injection (template-injection) # to prevent shell injection (template-injection)
run: | run: |
# The logic is executed within the shell using the env variables # The logic is executed within the shell using the env variables