diff --git a/.github/workflows/check-sca.yml b/.github/workflows/check-sca.yml index aefa2f6e..c96eba36 100644 --- a/.github/workflows/check-sca.yml +++ b/.github/workflows/check-sca.yml @@ -3,6 +3,7 @@ name: SCA Check on: pull_request: merge_group: + workflow_call: permissions: id-token: write @@ -10,7 +11,7 @@ permissions: jobs: verify-sca: - runs-on: warp-custom-ubuntu-24-04 + runs-on: sonar-xs # `id-token: write` (above) makes GitHub mint an OIDC token, which the # check-sca composite action exchanges with Vault for SonarQube # credentials. Per the SonarSource OIDC standard, the `environment` diff --git a/.github/workflows/test-check-sca.yml b/.github/workflows/test-check-sca.yml new file mode 100644 index 00000000..3d9084c4 --- /dev/null +++ b/.github/workflows/test-check-sca.yml @@ -0,0 +1,15 @@ +--- +name: Test SCA Check +on: + pull_request: + paths: + - .github/workflows/check-sca.yml + - .github/workflows/test-check-sca.yml + +permissions: + id-token: write + contents: read + +jobs: + verify-sca: + uses: ./.github/workflows/check-sca.yml