From 673478bce574254fdc6009c70ce5529645401abf Mon Sep 17 00:00:00 2001 From: Brian Date: Mon, 10 Aug 2026 10:51:54 -0500 Subject: [PATCH] BUILD-12243: Move verify-sca to sonar-xs Run the check-sca verify-sca job on the right-sized sonar-xs runner instead of the WarpBuild custom Ubuntu runner. --- .github/workflows/check-sca.yml | 3 ++- .github/workflows/test-check-sca.yml | 15 +++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/test-check-sca.yml diff --git a/.github/workflows/check-sca.yml b/.github/workflows/check-sca.yml index aefa2f6e..c96eba36 100644 --- a/.github/workflows/check-sca.yml +++ b/.github/workflows/check-sca.yml @@ -3,6 +3,7 @@ name: SCA Check on: pull_request: merge_group: + workflow_call: permissions: id-token: write @@ -10,7 +11,7 @@ permissions: jobs: verify-sca: - runs-on: warp-custom-ubuntu-24-04 + runs-on: sonar-xs # `id-token: write` (above) makes GitHub mint an OIDC token, which the # check-sca composite action exchanges with Vault for SonarQube # credentials. Per the SonarSource OIDC standard, the `environment` diff --git a/.github/workflows/test-check-sca.yml b/.github/workflows/test-check-sca.yml new file mode 100644 index 00000000..3d9084c4 --- /dev/null +++ b/.github/workflows/test-check-sca.yml @@ -0,0 +1,15 @@ +--- +name: Test SCA Check +on: + pull_request: + paths: + - .github/workflows/check-sca.yml + - .github/workflows/test-check-sca.yml + +permissions: + id-token: write + contents: read + +jobs: + verify-sca: + uses: ./.github/workflows/check-sca.yml