feat: Moonlight-host (Sunshine/Apollo/Wolf) client support #484
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security | |
| # PR-time security gates for dish-android. Pulls the shared jobs from | |
| # this repo's local copy of `_security.yml` (action-pin lint, allowlist- | |
| # expiry, OSV-Scanner, dependency-review, gitleaks). CodeQL lives in | |
| # codeql.yml because it has its own matrix. | |
| # | |
| # Known-vulnerable-dependency coverage: OSV-Scanner and dependency-review | |
| # here (GitHub/OSV advisory data, exact Maven coordinates), Grype against | |
| # release artifacts in release.yml (NVD + GHSA), and Dependabot updates. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| schedule: | |
| - cron: "0 6 * * 1" | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| security-events: write | |
| jobs: | |
| shared: | |
| uses: ./.github/workflows/_security.yml | |
| with: | |
| # OSV recognises Gradle build files; let it scan the worktree. | |
| osv_scan_paths: | | |
| . | |
| gitleaks_enabled: true | |
| dependency_review_enabled: true | |
| action_pin_lint_enabled: true | |
| allowlist_expiry_enabled: true | |