Skip to content

Commit ab111ce

Browse files
Remove low-use/value GitHub Action dependencies
- `AppOmni-Labs/heisenberg-ssc-gha`: low quality reports that I mostly if not entirely ignore. Also doesn't pin its transitive dependencies. - `chains-project/dirty-waters-action`: low value unpinnable action that sometimes starts acting up out of nowhere. - `ericcornelissen/odgen-action`: low value static analysis, unpinnable.
1 parent 02b13bb commit ab111ce

3 files changed

Lines changed: 0 additions & 65 deletions

File tree

.github/workflows/audit-dev.yml

Lines changed: 0 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -37,48 +37,6 @@ jobs:
3737
run: npm clean-install
3838
- name: Audit for deprecations
3939
run: npm run audit:deprecations
40-
dirty-waters:
41-
name: Dirty Waters
42-
runs-on: ubuntu-24.04
43-
permissions:
44-
pull-requests: write # To comment on a Pull Request
45-
steps:
46-
- name: Checkout repository
47-
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
48-
with:
49-
persist-credentials: false
50-
- name: Verify action checksums
51-
uses: ./.github/actions/ghasum
52-
- name: Run Dirty-waters analysis
53-
uses: chains-project/dirty-waters-action@v1.11.52
54-
with:
55-
allow_pr_comment: true
56-
comment_on_commit: false
57-
config: ./config/dirty-waters.json
58-
github_token: ${{ secrets.GITHUB_TOKEN }}
59-
gradual_report: false
60-
ignore_cache: false
61-
package_manager: npm
62-
specified_smells: --check-source-code --check-source-code-sha
63-
x_to_fail: 0
64-
heisenberg:
65-
name: Heisenberg
66-
runs-on: ubuntu-24.04
67-
if: ${{ github.event_name == 'pull_request' }}
68-
permissions:
69-
pull-requests: write # To comment on a Pull Request
70-
steps:
71-
- name: Checkout repository
72-
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
73-
with:
74-
persist-credentials: false
75-
- name: Verify action checksums
76-
uses: ./.github/actions/ghasum
77-
- name: Run Heisenberg analysis
78-
uses: AppOmni-Labs/heisenberg-ssc-gha@v1.0.3
79-
with:
80-
add_security_label: false
81-
package_file: package-lock.json
8240
vulnerabilities:
8341
name: Vulnerabilities
8442
runs-on: ubuntu-24.04

.github/workflows/checks.yml

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -137,20 +137,6 @@ jobs:
137137
run: |
138138
URL="${GH_URL}/${REPO}/pull/${NUMBER}"
139139
gh pr comment "${URL}" --body "${COMMENT}"
140-
odgen:
141-
name: ODGen
142-
runs-on: ubuntu-24.04
143-
steps:
144-
- name: Checkout repository
145-
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
146-
with:
147-
persist-credentials: false
148-
- name: Verify action checksums
149-
uses: ./.github/actions/ghasum
150-
- name: Perform ODGen analysis
151-
uses: ericcornelissen/odgen-action@v1.1.1
152-
with:
153-
vulnerability_type: os_command, code_exec, proto_pollution, ipt, xss, path_traversal
154140
reproducible:
155141
name: Reproducible build
156142
runs-on: ubuntu-24.04

.github/workflows/gha.sum

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,30 +1,21 @@
11
version 1
22

3-
AppOmni-Labs/heisenberg-ssc-gha@v1.0.3 fAlZiG1lk7C4GW5zoFzG+9cCYqtF+x3Fw5IoCI8o4Vw=
4-
actions-ecosystem/action-add-labels@v1 TAe5KMeDutoqa65ydmV9YdFK+RtBnXZIp9SA3PQi/Pk=
5-
actions/cache@v4.2.3 A/Paejdu47oer1Zf9zbtOgbMTG3OmOiXsgB6oodFIOU=
63
actions/cache@v5.0.3 9j/LRKexFfxHWzVbStH0MAw4ePL9cNrhLNSjmONs+Is=
74
actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 lqcOZgWyTneOKF0riqdP6+vaHfT8MJqXvjKe4fdsTjs=
85
actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd s/NQMxIFsmRFac7hJyF3QlZIJ3YbGpNiS5zPtPJgB1s=
96
actions/checkout@d632683dd7b4114ad314bca15554477dd762a938 e6ng7MJDyAPkTZ/6d/plZK2YhZRzJZvxhYAPUPpNAzc=
107
actions/create-github-app-token@7e473efe3cb98aa54f8d4bac15400b15fad77d94 yeXVQWVRe7LlkqUY9Xco8LpJ+V2avq5OP33tZYbGnXk=
118
actions/create-github-app-token@v2.2.0 yeXVQWVRe7LlkqUY9Xco8LpJ+V2avq5OP33tZYbGnXk=
12-
actions/github-script@v7 szdLNpz8Va2xlE22zZc+JipfRGfMZw13OOZGxLuaGqM=
139
actions/labeler@v6.0.0 vIbx/9sZYOT56jy87glclJ87y9Vd1y4SPRfS862VkeA=
1410
actions/setup-node@v4.3.0 42jvLeHkfmB6GxoSth6I7EvbxtWh47IRGuqDDrNCYhM=
1511
actions/setup-node@v6.2.0 s1RfTSV8Ah9TAmSOTO+0UiR51/XGkC4lrr1YZi7yBKo=
16-
actions/setup-python@v5 MTHBGEHwb+MeIw3xRLiVuM/uyRfuK8hlVXL+Z/yEA8c=
17-
actions/setup-python@v5.6.0 MTHBGEHwb+MeIw3xRLiVuM/uyRfuK8hlVXL+Z/yEA8c=
1812
actions/upload-artifact@v6.0.0 pGNYwgnMwE8lQptaxeFNnwBLuWlkpSuQLb+kTVzspLg=
1913
asdf-vm/actions@b7bcd026f18772e44fe1026d729e1611cc435d47 NTSr2fG0/s/purlk1j8nFi/OZXSGAlRzB+GB0KKzhTk=
2014
asdf-vm/actions@v4.0.0 eGZn+tf2SoEwu2pptGEHoXu4mnO/zJHvqWldHAhWmtM=
21-
chains-project/dirty-waters-action@v1.11.52 JTXn8ep3K5YnkSpNVyVVe85RAxg2eQ2X+TKP5A6JgyA=
22-
ericcornelissen/odgen-action@v1.1.1 UZ+sIMi5lX7uHvMbJfQf/qlN2ZPmUbCCgZkQmy4RZvQ=
2315
ericcornelissen/tool-versions-update-action@v2.2.0 hEKQk7PtggFp4V/aUnbNy7/VbpQsYTUurzocvHKI3Qw=
2416
github/codeql-action@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 cKk/jC+AF7SIc9AV9Pk3XEbI+kND9NsY4T1AfQQkPzY=
2517
github/codeql-action@v4.32.0 cKk/jC+AF7SIc9AV9Pk3XEbI+kND9NsY4T1AfQQkPzY=
2618
ncipollo/release-action@b7eabc95ff50cbeeedec83973935c8f306dfcd0b x49H6hPD8AWXRzcWpr1XIT5RoPcHJ/4QprD1vkG7ZnA=
27-
peter-evans/create-or-update-comment@v4 EFrtkHrqAoarXp0g95Hzycnm7OHxBYO7kYpazfHUhPQ=
2819
peter-evans/create-pull-request@84ae59a2cdc2258d6fa0732dd66352dddae2a412 OLxtm/mOdNIRqAWWLjgrnEjNt0OL1Lak9MN9hbOXQNc=
2920
peter-evans/create-pull-request@v8.0.0 Luap3+Di9HmjSpYTqM9ZzZHk1DBFrDgIwuguQ2Bty1k=
3021
stefanzweifel/git-auto-commit-action@28e16e81777b558cc906c8750092100bbb34c5e3 g4PCgPHeeaVpSPTRcoBKth4QnrZGGQXwBEoEAsAXivs=

0 commit comments

Comments
 (0)