chore(deps): update github/codeql-action action to v3.28.0 #3005
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Pull Request π₯ | |
concurrency: | |
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} | |
cancel-in-progress: true | |
on: | |
pull_request_target: | |
merge_group: | |
permissions: | |
pull-requests: read | |
jobs: | |
push-comment: | |
name: Create comments βοΈ | |
if: ${{ always() && !cancelled() && github.repository == 'jellyfin/jellyfin-vue' }} | |
uses: ./.github/workflows/__job_messages.yml | |
secrets: inherit | |
with: | |
commit: ${{ github.event.pull_request.head.sha }} | |
in_progress: true | |
comment: true | |
automation: | |
name: Automation ποΈ | |
if: ${{ always() && !cancelled() && github.repository == 'jellyfin/jellyfin-vue' }} | |
uses: ./.github/workflows/__automation.yml | |
secrets: inherit | |
semantic-commits: | |
if: ${{ always() && !cancelled() && github.repository == 'jellyfin/jellyfin-vue' }} | |
runs-on: ubuntu-latest | |
name: Semantic Pull Request π | |
steps: | |
- name: Validate PR title π | |
uses: amannn/[email protected] | |
env: | |
GITHUB_TOKEN: ${{ secrets.JF_BOT_TOKEN }} | |
with: | |
subjectPattern: ^(?![A-Z]).+$ | |
subjectPatternError: | | |
The subject "{subject}" found in the pull request title "{title}" | |
didn't match the configured pattern. Please ensure that the subject | |
doesn't start with an uppercase character. | |
label: | |
name: Labeling π·οΈ | |
if: ${{ always() && !cancelled() && github.repository == 'jellyfin/jellyfin-vue'}} | |
runs-on: ubuntu-latest | |
steps: | |
- name: Label depending on modified files | |
uses: actions/[email protected] | |
with: | |
sync-labels: true | |
repo-token: ${{ secrets.JF_BOT_TOKEN }} | |
build: | |
name: Build ποΈ | |
if: ${{ always() && !cancelled() }} | |
uses: ./.github/workflows/__package.yml | |
# Needed for attestation publication | |
permissions: | |
id-token: write | |
attestations: write | |
with: | |
commit: ${{ github.event.pull_request.head.sha }} | |
quality_checks: | |
name: Quality checks ππ§ͺ | |
if: ${{ always() && !cancelled() }} | |
uses: ./.github/workflows/__quality_checks.yml | |
permissions: {} | |
with: | |
commit: ${{ github.event.pull_request.head.sha }} | |
codeql: | |
name: GitHub CodeQL π¬ | |
if: ${{ always() && !cancelled() }} | |
uses: ./.github/workflows/__codeql.yml | |
permissions: | |
actions: read | |
contents: read | |
security-events: write | |
with: | |
commit: ${{ github.event.pull_request.head.sha }} | |
deploy: | |
name: Deploy π | |
uses: ./.github/workflows/__deploy.yml | |
if: ${{ always() && !cancelled() && github.repository == 'jellyfin/jellyfin-vue' }} | |
needs: | |
- push-comment | |
- build | |
permissions: | |
contents: read | |
deployments: write | |
secrets: inherit | |
with: | |
# If the PR is from the master branch of a fork, append the fork's name to the branch name | |
branch: ${{ github.event.pull_request.head.repo.full_name != github.repository && github.event.pull_request.head.ref == 'master' && format('{0}/{1}', github.event.pull_request.head.repo.full_name, github.event.pull_request.head.ref) || github.event.pull_request.head.ref }} | |
comment: true | |
commit: ${{ github.event.pull_request.head.sha }} |