chore: migrate to reusable workflows - #186
Merged
Merged
Conversation
- Replace local sast.yaml with inline local copy (public repo restriction) - Replace local trivy-scan.yaml with inline local copy (public repo restriction) - Add verify-linked-issue.yaml as inline local copy (public repo restriction) - Replace local back-merge-handler.yml with reusable back-merge workflow - Add renovate.json with github-actions only updates, schedule Wednesday Note: This repo is public; GitHub does not allow public repos to call reusable workflows from a private repo. Workflow logic mirrors regulaforensics/reusable-workflows exactly; SHA pins kept current by Renovate.
…ings (#63089) 230 pre-existing findings in generated Python client code. Not blocking migration — tracked for remediation separately.
amos-regula
approved these changes
Aug 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
https://redmine.regulaforensics.com/issues/63089
Summary
Migrate
FaceSDK-web-python-clientto use standardized security scanning workflows.Changes
sast.yaml— replaced old local workflow with inline copy matching reusable-workflows logic; SHA pins addedtrivy-scan.yaml— replaced old local workflow with inline copy with SHA pinsverify-linked-issue.yaml— added inline local copy (inlinedgithub-scriptlogic)back-merge.yaml— replaced old shell-basedback-merge-handler.ymlwith call toreusable-workflows/back-merge.yaml@mainrenovate.json— added; tracksgithub-actionsonly, schedule: WednesdayRequired after merge
semgrep-oss/scantrivy-scanPR has a linked issue.