mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-09-29 19:04:59 +01:00
Missed in #6848 (had it sitting in my workspace uncommitted, apparently have gotten too used to jj; using git here) Assisted-by: Google Antigravity with Gemini
41 lines
1.1 KiB
Markdown
41 lines
1.1 KiB
Markdown
# Workflows
|
|
|
|
<!--
|
|
Part of the Carbon Language project, under the Apache License v2.0 with LLVM
|
|
Exceptions. See /LICENSE for license information.
|
|
SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
|
|
-->
|
|
|
|
## Hardening
|
|
|
|
Workflows are hardened using
|
|
[Step Security tool](https://app.stepsecurity.io/secureworkflow). Findings for
|
|
the "Harden Runner" steps are
|
|
[available online](https://app.stepsecurity.io/github/carbon-language/carbon-lang/actions/runs).
|
|
|
|
### Allowed endpoints
|
|
|
|
Most jobs only have a few endpoints, but due to tools which do downloads, a few
|
|
have significantly more. These are:
|
|
|
|
- clangd_tidy.yaml (Bazel)
|
|
- pre_commit.yaml (Bazel, pre-commit)
|
|
- nightly_release.yaml (Bazel)
|
|
- tests.yaml (Bazel)
|
|
|
|
When updating one of these, consider updating all of them.
|
|
|
|
We try to keep `allowed-endpoints` with one per line. Prettier wants to wrap
|
|
them, which we fix this with `prettier-ignore`.
|
|
|
|
## Testing
|
|
|
|
We keep around an `action-test` branch in carbon-lang, which can be used to test
|
|
triggers with `push:` configurations. For example:
|
|
|
|
```
|
|
on:
|
|
push:
|
|
branches: [action-test]
|
|
```
|