Skip to content

fix(ci): use safe dependency review trigger - #122

Open
yvonnedevlinrh wants to merge 1 commit into
unbound-force:mainfrom
yvonnedevlinrh:opsx/fix-dependency-review-trigger
Open

yvonnedevlinrh wants to merge 1 commit into
unbound-force:mainfrom
yvonnedevlinrh:opsx/fix-dependency-review-trigger

Conversation

@yvonnedevlinrh

Copy link
Copy Markdown
Contributor

Summary

PR #110 introduced automated Dependabot reviews and approvals, but its use of pull_request_target caused MegaLinter's zizmor security check to fail.

This follow-up:

  • replaces pull_request_target with the ComplyTime pull_request pattern
  • keeps the existing Dependabot-only, risk, release-age, human-veto, and head-SHA safeguards
  • adds a regression assertion preventing pull_request_target from being reintroduced
  • updates the OpenSpec design to match the implementation

Verification

  • go test ./internal/workflowtest -count=1 -race
  • make check-coverage
  • go vet ./...
  • govulncheck ./...
  • golangci-lint run ./...
  • actionlint
  • zizmor
  • openspec validate automate-dependency-update

All checks passed. Zizmor reports no findings.

@yvonnedevlinrh
yvonnedevlinrh requested a review from a team as a code owner October 2, 2026 10:20
@yvonnedevlinrh yvonnedevlinrh self-assigned this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants