diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 59f1c7f2..6e5574ec 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -2,7 +2,7 @@ name: Semgrep on: merge_group: - pull_request_target: + pull_request: types: - opened - synchronize @@ -20,15 +20,8 @@ concurrency: cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} jobs: - authorize: - name: Authorize - environment: ${{ github.actor != 'dependabot[bot]' && github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository && 'external' || 'internal' }} - runs-on: ubuntu-latest - steps: - - run: true run: - needs: authorize # Require approval before running on forked pull requests name: Check for Vulnerabilities runs-on: ubuntu-latest diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 140afaf6..4bdd8282 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -3,7 +3,7 @@ name: Snyk on: merge_group: workflow_dispatch: - pull_request_target: + pull_request: types: - opened - synchronize @@ -21,15 +21,9 @@ concurrency: cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} jobs: - authorize: - name: Authorize - environment: ${{ github.actor != 'dependabot[bot]' && github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository && 'external' || 'internal' }} - runs-on: ubuntu-latest - steps: - - run: true + check: - needs: authorize name: Check for Vulnerabilities runs-on: ubuntu-latest diff --git a/.snyk b/.snyk index 0524dbc6..2c0f940d 100644 --- a/.snyk +++ b/.snyk @@ -5,16 +5,16 @@ ignore: SNYK-JAVA-COMFASTERXMLWOODSTOX-3091135: - '*': reason: Latest version of dokka has this vulnerability - expires: 2024-08-31T12:08:37.765Z + expires: 2024-10-31T12:19:35.000Z created: 2024-08-01T12:08:37.770Z SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744: - '*': reason: Latest version of dokka has this vulnerability - expires: 2024-08-31T12:08:55.924Z + expires: 2024-10-31T12:19:35.000Z created: 2024-08-01T12:08:55.927Z SNYK-JAVA-COMFASTERXMLJACKSONCORE-7569538: - '*': reason: Latest version of dokka has this vulnerability - expires: 2024-08-31T12:08:02.966Z + expires: 2024-10-31T12:19:35.000Z created: 2024-08-01T12:08:02.973Z patch: {}