Files
kubernetes.core/.github/workflows/security-check.yaml
GomathiselviS 6bb9cce51b feat(ci): add security check to block .claude/ and .vscode/ directories (#1173)
* feat(ci): add security check to block .claude/ and .vscode/ directories

Add workflow that calls the security_check_directories action from
cloud-content-ci-automation to fail PRs containing files under .claude/
or .vscode/ directories.

Integrates with all_green_check.yaml as a required job for PRs.

Ref: ACA-6411

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix(ci): suppress SonarCloud S7637 for reusable actions using @main

Internal reusable actions from ansible-network/github_actions and
ansible-collections/cloud-content-ci-automation use @main refs for
simpler maintenance. Suppress the 'use full commit SHA' rule for
workflow files.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix(ci): use correct org and pin action to commit SHA

Address review feedback:
- Change org from ansible-collections to ansible
- Pin to commit SHA 74b5fe87 instead of @main

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: add changelog fragment for security check workflow

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Update changelogs/fragments/1173-security-check-workflow.yml

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: Bianca Henderson <beeankha@gmail.com>
2026-07-02 16:48:56 -04:00

18 lines
430 B
YAML

---
name: Security Check
on: [workflow_call]
jobs:
security-check:
name: Block unsafe directories
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Check for blocked directories
uses: ansible/cloud-content-ci-automation/.github/actions/security_check_directories@74b5fe870e1d5346c5fcea332b97a6fb26f1ad8a