Add GitHub Security Actions Workflow #2
ci-main-pull-request-checks.yml
on: pull_request
call-ci-main-pr-check-pipeline
/
Checkout repository
4s
Echo stub version
2s
call-ci-main-pr-check-pipeline
/
Pre-compilation checks
3s
call-ci-main-pr-check-pipeline
/
Build and compilation
4s
call-ci-main-pr-check-pipeline
/
...
/
Complexity and SLOC generation
22s
call-ci-main-pr-check-pipeline
/
Language-specific pre-compilation steps and linting
0s
call-ci-main-pr-check-pipeline
/
Language-agnostic pre-compilation steps
0s
call-ci-main-pr-check-pipeline
/
...
/
Trufflehog
8s
call-ci-main-pr-check-pipeline
/
polaris-sast
0s
call-ci-main-pr-check-pipeline
/
run-blackduck-sca
0s
call-ci-main-pr-check-pipeline
/
Creating packaged binaries
0s
call-ci-main-pr-check-pipeline
/
...
/
Export SBOM from GitHub Dependency Graph API
6s
call-ci-main-pr-check-pipeline
/
...
/
Generate SBOM using Blackduck Tool
0s
call-ci-main-pr-check-pipeline
/
...
/
Generate MSFT SBOM
0s
call-ci-main-pr-check-pipeline
/
...
/
license_scout
0s
call-ci-main-pr-check-pipeline
/
...
/
Echo inputs
call-ci-main-pr-check-pipeline
/
...
/
SonarQube
call-ci-main-pr-check-pipeline
/
...
/
Echo inputs
call-ci-main-pr-check-pipeline
/
...
/
SonarQube
call-ci-main-pr-check-pipeline
/
...
/
Echo inputs
call-ci-main-pr-check-pipeline
/
...
/
SonarQube
Matrix: call-ci-main-pr-check-pipeline / Unit tests
call-ci-main-pr-check-pipeline
/
Creating Habitat packages
0s
call-ci-main-pr-check-pipeline
/
Publishing packages
0s
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
habitat-sh-sample-node-app-20250825181133-GitHub-sbom.csv
|
307 Bytes |
sha256:19cda080548c3ffb91a25121cb67a7fd2a6e45a3926b1a225e09e53a365a5a67
|
|
|
habitat-sh-sample-node-app-20250825181133-GitHub-sbom.json
|
7.93 KB |
sha256:112a06180514d2264f647342c6fd4407f89f3a7f3268d3d6c2c708370015b273
|
|
|
scc-output.txt
Expired
|
1.25 KB |
sha256:689b6262595f6b3555cd766b96a8d741a3d1d28e2e2c8cc4c96e79acc7b5bad2
|
|