Closed ramonpetgrave64 closed 1 month ago
@laurentsimon @mihaimaruseac @ianlewis
This seems a little bit more complex. Can this be done similar to guacsec/guac#953 (comment) ?
I used the gh
cli because it has some conveniences like setting up the correct remote branch for the PR. If we used actions/checkout
within a normal pull_request
event, then we wouldn't need to use gh
cli.
@kpk47 And I added some more Repo rules that make this workflow even safer to use. Safer than cloning the PR locally and running the untrusted code.
Thanks everyone for the reviews
Add a new Post-Commit workflow, to make these renovate-bot updates a bit easier. Previously, we had to clone the PR locally, run
make package
, and then push to the PR. Now we would just need to use the github UI to invoke this new workflow against the PR number. We could also copy this over to the slsa-github-generator repo.Testing.
Tested in my own private fork, where when applicable, it pushed a commit of changes to
dist/
folders