Skip to content

Ci/workflow file extension#48

Open
Shwelinhtet-PaloIT wants to merge 15 commits intomainfrom
ci/workflow-file-extension
Open

Ci/workflow file extension#48
Shwelinhtet-PaloIT wants to merge 15 commits intomainfrom
ci/workflow-file-extension

Conversation

@Shwelinhtet-PaloIT
Copy link
Copy Markdown
Contributor

No description provided.

Shwelinhtet-PaloIT and others added 9 commits March 15, 2026 11:15
Standardize workflow file naming convention by adding .yml extension
to the CodeQL dynamic workflow file for consistency with GitHub Actions
best practices and other workflow files in the repository.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…data

Remove deprecated .github/prompts/commit.md and add  to .github/skills/git-commit/SKILL.md; reduce example content to keep frontmatter focused.
This file sets up a CodeQL workflow for analyzing code in multiple languages, including configuration for triggers and job settings.
Add two test vulnerabilities to validate GHAS protection rules:
- HIGH: SQL injection via unsafeQuery() — java/sql-injection
- LOW: Predictable random seed via weakToken() — java/predictable-random

These will be removed after gate validation is confirmed.
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Mar 15, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 2bf7765.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Scanned Files

  • .github/workflows/ci.yml

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Mar 15, 2026

Test Results

8 tests   8 ✅  0s ⏱️
1 suites  0 💤
1 files    0 ❌

Results for commit 2bf7765.

♻️ This comment has been updated with latest results.

Comment thread src/main/java/com/example/HelloWorld.java Fixed
codeql job was commented out but needs: [sbom, codeql] still
referenced it causing workflow validation error. CodeQL scanning
is handled exclusively by codeql-dynamic.yml.
SQL injection and predictable random seed methods removed.
Gate validation confirmed — GHAS blocked merge on High severity.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants