Skip to content

Commit 89bb5d9

Browse files
authored
Merge pull request #186 from awslabs/fix/trufflehog-agpl-license-exemption
fix(ci): exempt trufflehog from AGPL-3.0 license check
2 parents 50e4c33 + 940eeca commit 89bb5d9

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

.github/dependabot.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ updates:
7777
- "dependencies"
7878
- "github-actions"
7979
commit-message:
80-
prefix: "chore(ci)"
80+
prefix: "ci"
8181
include: "scope"
8282
open-pull-requests-limit: 2
8383
groups:

.github/workflows/security-code.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -115,7 +115,7 @@ jobs:
115115
allow-licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, Unlicense
116116
# werkzeug 3.1.6 reports compound SPDX 'BSD-3-Clause AND LicenseRef-scancode-unknown-license-reference'
117117
# due to upstream metadata issue — it is BSD-3-Clause, exempt it from license check
118-
allow-dependencies-licenses: 'pkg:pypi/werkzeug'
118+
allow-dependencies-licenses: 'pkg:pypi/werkzeug, pkg:githubactions/trufflesecurity/trufflehog'
119119

120120
codeql-analysis:
121121
name: CodeQL Analysis

0 commit comments

Comments
 (0)