Skip to content

feat: Moonlight-host (Sunshine/Apollo/Wolf) client support #484

feat: Moonlight-host (Sunshine/Apollo/Wolf) client support

feat: Moonlight-host (Sunshine/Apollo/Wolf) client support #484

Workflow file for this run

name: Security
# PR-time security gates for dish-android. Pulls the shared jobs from
# this repo's local copy of `_security.yml` (action-pin lint, allowlist-
# expiry, OSV-Scanner, dependency-review, gitleaks). CodeQL lives in
# codeql.yml because it has its own matrix.
#
# Known-vulnerable-dependency coverage: OSV-Scanner and dependency-review
# here (GitHub/OSV advisory data, exact Maven coordinates), Grype against
# release artifacts in release.yml (NVD + GHSA), and Dependabot updates.
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
- cron: "0 6 * * 1"
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: read
security-events: write
jobs:
shared:
uses: ./.github/workflows/_security.yml
with:
# OSV recognises Gradle build files; let it scan the worktree.
osv_scan_paths: |
.
gitleaks_enabled: true
dependency_review_enabled: true
action_pin_lint_enabled: true
allowlist_expiry_enabled: true