Skip to content

QVAC-22740 infra: bump CodeScan caller to qvac-actions 0.3.0 - #26

Merged
GSServita merged 1 commit into
masterfrom
feat/codescan-bump-0.3.0
Jul 31, 2026
Merged

QVAC-22740 infra: bump CodeScan caller to qvac-actions 0.3.0#26
GSServita merged 1 commit into
masterfrom
feat/codescan-bump-0.3.0

Conversation

@GSServita

Copy link
Copy Markdown

🎯 What problem does this PR solve?

  • The CodeScan caller is pinned to qvac-actions 0.2.0, which predates the findings-export feature. Bumping to 0.3.0 gives this repo the downloadable security-scan-report artifact (findings.json + findings.md + per-language SARIF) on every run — the coverage/triage route while codeql-upload: never.

📝 How does it solve it?

  • Bumps the reusable-workflow pin 0.2.00.3.0. export-report defaults on, so no other change is needed.

🔐 Action pinning

  • tetherto/qvac-actions/.github/workflows/public-reusable-security.yml: be1d22629cc48b6dcc36645acc9e6d89cfaf54d8 # 0.2.0bbb0740e2a16b94371c7439e0e06945c5b68e759 # 0.3.0.

🧪 How was it tested?

  • Pinned to the immutable 0.3.0 tag commit. workflow_dispatch after merge confirms the security-scan-report artifact appears under the run's Artifacts.

Bump the reusable security workflow pin 0.2.0 -> 0.3.0 (SHA bbb0740e). 0.3.0
adds the findings-export artifact (export-report default on), so each run now
publishes a downloadable security-scan-report (findings.json/md + SARIF).
@GSServita
GSServita requested review from a team as code owners July 30, 2026 12:52
@github-actions

Copy link
Copy Markdown

Review Status

Current Status: ❌ PENDING
Approvals so far: none

Pending reviews: Needs 1 Management or Team Lead, and 1 more from Management, Team Lead, or Member.

@GSServita
GSServita merged commit 48361f9 into master Jul 31, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants