Skip to content

chore: migrate to reusable workflows - #366

Merged
andreinovik-regula merged 1 commit into
developfrom
63091-migrate-to-reusable-workflow
Aug 14, 2026
Merged

chore: migrate to reusable workflows#366
andreinovik-regula merged 1 commit into
developfrom
63091-migrate-to-reusable-workflow

Conversation

@andreinovik-regula

Copy link
Copy Markdown
Contributor

https://redmine.regulaforensics.com/issues/63091

Summary

Migrate DocumentReader-web-openapi to use standardized security scanning workflows.

⚠️ Public repo restriction: GitHub does not allow public repositories to call reusable workflows from a private repository. Workflow files below are local copies that mirror regulaforensics/reusable-workflows exactly, with SHA-pinned actions. Renovate keeps pins up-to-date.

Changes

  • sast.yaml — added inline local copy; exclude_paths: .github/workflows to suppress findings in existing workflow files with mutable tags; SHA-pinned
  • trivy-scan.yaml — added inline local copy; SHA-pinned
  • verify-linked-issue.yaml — added inline local copy; SHA-pinned
  • back-merge.yaml — replaced old back-merge-handler.yml with reusable-workflows/back-merge.yaml@f9848fa
  • renovate.json — updated to canonical template

- Add sast.yaml as inline local copy (public repo), exclude .github/workflows; SHA-pinned
- Add trivy-scan.yaml as inline local copy (public repo); SHA-pinned
- Add verify-linked-issue.yaml as inline local copy (public repo); SHA-pinned
- Replace back-merge-handler.yml with reusable back-merge@f9848fa (main)
- Update renovate.json to canonical template
@andreinovik-regula
andreinovik-regula merged commit fa010ef into develop Aug 14, 2026
8 checks passed
@andreinovik-regula
andreinovik-regula deleted the 63091-migrate-to-reusable-workflow branch August 14, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants