Skip to content

Fix/GitHub workflows - #1

Merged
kmilodenisglez merged 3 commits into
hyperledger:mainfrom
kmilodenisglez:fix/github-workflows
Sep 25, 2026
Merged

kmilodenisglez merged 3 commits into
hyperledger:mainfrom
kmilodenisglez:fix/github-workflows

Conversation

@kmilodenisglez

Copy link
Copy Markdown
Contributor

This pull request makes significant improvements to the project's GitHub Actions workflows and dependency management. The main goals are to modernize, modularize, and secure CI/CD processes by introducing reusable workflow templates, pinning action versions by commit hash for better security, and consolidating dependency update policies. Additionally, the workflows now include clearer copyright and license headers.

Key changes are grouped below:

Workflow Modernization and Modularity

  • Replaced the old test.yaml workflow with a new, more flexible test.yml that supports workflow inputs and includes commented templates for integration and Docker image tests. Other workflows (push.yml, pull_request.yml, scheduled.yml, scan.yml, scheduled-scan.yml) now reuse this template for consistency and maintainability. [1] [2] [3] [4] [5] [6]
  • Added new scheduled workflows (scheduled.yml, scheduled-scan.yml) to automate regular builds and vulnerability scans, ensuring both released and unreleased code are checked for issues. [1] [2] [3]

Security and Dependency Management

  • Updated all GitHub Actions in workflows to be pinned by commit SHA, improving supply chain security and aligning with best practices. [1] [2] [3] [4]
  • Introduced a .github/dependabot.yml configuration to automate updates for both GitHub Actions and Python dependencies, with grouping for easier management.

General Improvements and Clean-up

  • Added copyright and SPDX license headers to all workflow and configuration files for legal clarity and consistency. [1] [2] [3] [4] [5] [6] [7] [8] [9]
  • Removed the obsolete test.yaml workflow file in favor of the new test.yml.

These changes collectively improve maintainability, security, and clarity for CI/CD in the project.

… scheduled builds

Signed-off-by: kmilo <kmilo.denis.glez@yandex.com>
…b to 'Unit test'

Signed-off-by: kmilo <kmilo.denis.glez@yandex.com>
…ts replacement.

Signed-off-by: kmilo <kmilo.denis.glez@yandex.com>
@kmilodenisglez
kmilodenisglez merged commit 091e430 into hyperledger:main Sep 25, 2026
4 checks passed
@kmilodenisglez
kmilodenisglez deleted the fix/github-workflows branch September 25, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant