mirror of https://github.com/garrytan/gstack.git
dependency-review.yml rode mutable refs (@v4 resolves to a BRANCH on that repo) inside the one workflow whose job is supply-chain hygiene — now commit-pinned like its siblings, with dependabot keeping the pins fresh. gate-secret-scan.mjs crashed with an unhandled EPIPE on oversize diffs (the designed report.oversize branch was unreachable: the scanner emits no JSON on refusal) — the pipe write now tolerates early exit and a missing report is an explicit fail-closed exit 1. Oversize + broken-scanner legs pinned. |
||
|---|---|---|
| .. | ||
| docker | ||
| scripts | ||
| workflows | ||
| PULL_REQUEST_TEMPLATE.md | ||
| actionlint.yaml | ||
| dependabot.yml | ||