Compare commits

..

1 Commits

Author SHA1 Message Date
Andrew Eisenberg
c55c1eedf6 Avoid using pull_request_target
Move to using `pull_request` and a permissions block.
2021-10-21 10:50:01 -07:00
4 changed files with 9 additions and 7 deletions

View File

@@ -60,7 +60,6 @@ jobs:
- uses: ./../action/analyze
with:
output: ${{ runner.temp }}/results
upload-database: false
env:
TEST_MODE: true
- name: Assert Results

View File

@@ -1,13 +1,17 @@
name: Update dependencies
on:
pull_request_target:
pull_request:
types: [opened, synchronize, reopened, ready_for_review, labeled]
permissions:
issues: write
contents: write
jobs:
update:
name: Update dependencies
runs-on: macos-latest
if: contains(github.event.pull_request.labels.*.name, 'Update dependencies') && (github.event.pull_request.head.repo.full_name == 'github/codeql-action')
if: contains(github.event.pull_request.labels.*.name, 'Update dependencies')
steps:
- name: Checkout repository
uses: actions/checkout@v2
@@ -24,8 +28,8 @@ jobs:
env:
BRANCH: '${{ github.head_ref }}'
run: |
git fetch origin "$BRANCH" --depth=1
git checkout "origin/$BRANCH"
git fetch
git checkout $BRANCH
sudo npm install --force -g npm@latest
npm install
npm ci

View File

@@ -1,6 +1,6 @@
# CodeQL Action and CodeQL Runner Changelog
## 1.0.20 - 25 Oct 2021
## [UNRELEASED]
No user facing changes.

View File

@@ -28,7 +28,6 @@ steps:
- uses: ./../action/analyze
with:
output: "${{ runner.temp }}/results"
upload-database: false
env:
TEST_MODE: true
- name: Assert Results