diff --git a/.github/workflows/cmake-multi-platform.yml b/.github/workflows/cmake-multi-platform.yml index ea553934..24c34d67 100644 --- a/.github/workflows/cmake-multi-platform.yml +++ b/.github/workflows/cmake-multi-platform.yml @@ -148,7 +148,7 @@ jobs: repository: 'nam20485/OdbDesignTestData' path: 'OdbDesignTestData' ref: 'main' - token: ${{ secrets.ODBDESIGN_TESTDATA_ACCESS_TOKEN }} + #token: ${{ secrets.ODBDESIGN_TESTDATA_ACCESS_TOKEN }} - name : Export ODB_TEST_DATA_DIR uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 63ae082c..3c58ad21 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -16,17 +16,6 @@ permissions: jobs: - dependency-submission: - runs-on: ubuntu-22.04 - permissions: - id-token: write - contents: write - - steps: - - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 - - name: Component detection - uses: advanced-security/component-detection-dependency-submission-action@v0.0.2 - dependency-review: runs-on: ubuntu-22.04 permissions: @@ -37,6 +26,9 @@ jobs: - name: 'Checkout Repository' uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 + - name: Component detection + uses: advanced-security/component-detection-dependency-submission-action@v0.0.2 + - name: 'Dependency Review' uses: actions/dependency-review-action@4901385134134e04cec5fbe5ddfe3b2c5bd5d976 # v4.0.0 with: diff --git a/.github/workflows/sbom-generate-submit.yml b/.github/workflows/sbom-generate-submit.yml index 240f752e..a89ece22 100644 --- a/.github/workflows/sbom-generate-submit.yml +++ b/.github/workflows/sbom-generate-submit.yml @@ -2,7 +2,7 @@ name: SBOM Generate and Submit on: push: - branches: [ "development", "release" ] + branches: [ "main", "release", "development", "nam20485" ] workflow_dispatch: permissions: @@ -11,7 +11,9 @@ permissions: jobs: build: runs-on: ubuntu-22.04 - permissions: read-all + permissions: + id-token: write + contents: write steps: - name: Checkout Code @@ -26,5 +28,5 @@ jobs: - name: SBOM Upload uses: advanced-security/spdx-dependency-submission-action@v0.0.1 with: - filePath: ${{steps.sbom-generate.outputs.fileName }} + filePath: ${{ steps.sbom-generate.outputs.fileName }} \ No newline at end of file