fix(ui): measure the wizard banner's compact mode on the window; pin … #277
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security | |
| # CodeQL is not here: it needs its own matrix, so it lives in codeql.yml. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| schedule: | |
| - cron: "0 6 * * 1" # weekly Monday 06:00 UTC | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| # Must be a superset of the permissions _security.yml declares, or the call | |
| # fails. See the block in that file. | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| jobs: | |
| shared: | |
| uses: ./.github/workflows/_security.yml | |
| with: | |
| # Whole worktree: there is no vendored source, so OSV only has the | |
| # manifests it can recognise (vcpkg.json, CMake fetch declarations). | |
| osv_scan_paths: | | |
| . | |
| gitleaks_enabled: true | |
| dependency_review_enabled: true | |
| action_pin_lint_enabled: true | |
| allowlist_expiry_enabled: true |