Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Address security findings
  • Loading branch information
l46kok committed Oct 2, 2026
commit 429d0173444fb37f3540a0b7c1ce148c70d1e0c5
39 changes: 27 additions & 12 deletions .github/workflows/workflow.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,20 +14,25 @@ concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
Bazel-Build-Java8:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event."
- run: echo "🐧 Job is running on a ${{ runner.os }} server!"
- run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}."
- run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}."
- name: Check out repository code
uses: actions/checkout@v6
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false
- name: Mark job start
run: touch "$RUNNER_TEMP/job-start"
- name: Setup Bazel
uses: bazel-contrib/setup-bazel@0.18.0
uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0
with:
# Store build cache per workflow.
disk-cache: ${{ github.workflow }}-${{ github.job }}
Expand All @@ -48,21 +53,25 @@ jobs:
du -sh ~/.cache/bazel-disk
find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete
du -sh ~/.cache/bazel-disk
- run: echo "🍏 This job's status is ${{ job.status }}."
- run: echo "🍏 This job's status is ${JOB_STATUS}."
env:
JOB_STATUS: ${{ job.status }}

Bazel-Tests:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event."
- run: echo "🐧 Job is running on a ${{ runner.os }} server!"
- run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}."
- run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}."
- name: Check out repository code
uses: actions/checkout@v6
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false
- name: Mark job start
run: touch "$RUNNER_TEMP/job-start"
- name: Setup Bazel
uses: bazel-contrib/setup-bazel@0.18.0
uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0
with:
# Store build cache per workflow.
disk-cache: ${{ github.workflow }}-${{ github.job }}
Expand All @@ -81,7 +90,9 @@ jobs:
du -sh ~/.cache/bazel-disk
find ~/.cache/bazel-disk -type f ! -newer "$RUNNER_TEMP/job-start" -delete
du -sh ~/.cache/bazel-disk
- run: echo "🍏 This job's status is ${{ job.status }}."
- run: echo "🍏 This job's status is ${JOB_STATUS}."
env:
JOB_STATUS: ${{ job.status }}

# -- Start of Maven Conformance Tests (Ran only when there's version changes) --
Maven-Conformance:
Expand All @@ -90,17 +101,21 @@ jobs:
steps:
- run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event."
- run: echo "🐧 Job is running on a ${{ runner.os }} server!"
- run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}."
- run: echo "🔎 The name of your branch is ${GITHUB_REF} and your repository is ${GITHUB_REPOSITORY}."
- name: Check out repository code
uses: actions/checkout@v6
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
# Full history so changed-files doesn't need credentials to fetch more.
fetch-depth: 0
persist-credentials: false
- name: Get changed files
id: changed_file
uses: tj-actions/changed-files@v47
uses: tj-actions/changed-files@24d32ffd492484c1d75e0c0b894501ddb9d30d62 # v47.0.0
with:
files: publish/cel_version.bzl
- name: Setup Bazel
if: steps.changed_file.outputs.any_changed == 'true'
uses: bazel-contrib/setup-bazel@0.18.0
uses: bazel-contrib/setup-bazel@083175551ceeceebc757ebee2127fde78840ca77 # 0.18.0
with:
# Store build cache per workflow.
disk-cache: ${{ github.workflow }}-${{ github.job }}
Expand Down
Loading