Repository navigation
chore(ci): bump github/codeql-action/upload-sarif from 4.37.7 to 4.38.0 #232
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: SPDX Header Check | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| # Manual runs, from Actions → SPDX Header Check → Run workflow. Same reasoning | |
| # as CI: a required check you cannot replay is a trap when the failure was | |
| # GitHub's rather than the code's. | |
| workflow_dispatch: | |
| jobs: | |
| license-check: | |
| runs-on: ubuntu-latest | |
| # This job only reads the repository. Without an explicit block it would | |
| # inherit the default token scopes, which are far wider than it needs. | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| # Nothing here pushes, so there is no reason to leave the token in | |
| # .git/config for later steps to reach. | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: '22' | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10 | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Verify SPDX headers | |
| run: pnpm license:check |