diff options
| author | Yuriy Andamasov <yuriy@andamasov.com> | 2026-06-01 12:39:44 +0300 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-06-01 12:39:44 +0300 |
| commit | cd545b46703b25c63767bd3fc7f12e2bddc7f9ad (patch) | |
| tree | 6975c9f7ee034f80afdacfbd60b044821b8ed95c | |
| parent | be56cc2590c61decb26432b563e5181b27039b78 (diff) | |
| parent | f92320675f909492bc7ab69975dbc3f0a0f5a0ef (diff) | |
| download | libpam-tacplus-cd545b46703b25c63767bd3fc7f12e2bddc7f9ad.tar.gz libpam-tacplus-cd545b46703b25c63767bd3fc7f12e2bddc7f9ad.zip | |
Merge pull request #18 from vyos/ci/lts-name-check
T8943: ci: add lts-name-check advisory caller
| -rw-r--r-- | .github/workflows/lts-name-check.yml | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/.github/workflows/lts-name-check.yml b/.github/workflows/lts-name-check.yml new file mode 100644 index 0000000..91fd9b5 --- /dev/null +++ b/.github/workflows/lts-name-check.yml @@ -0,0 +1,21 @@ +# .github/workflows/lts-name-check.yml +# DO NOT EDIT — managed by mirror-pipeline rollout. +name: LTS-name advisory check + +# pull_request_target (NOT pull_request) so the workflow runs with base-repo +# secrets even on fork PRs. The reusable workflow does NOT check out PR code +# (only reads title/body from the event payload), so the standard +# pull_request_target exploitation vector (running fork code with elevated +# secrets) does not apply. +on: + pull_request_target: + types: [opened, edited] + branches: [rolling] + +permissions: {} + +jobs: + call: + if: github.repository_owner == 'vyos' + uses: vyos/.github/.github/workflows/lts-name-check-reusable.yml@production + secrets: inherit |
