Skip to content

fix(ci): pin third-party actions to full commit SHAs (#387) #717

fix(ci): pin third-party actions to full commit SHAs (#387)

fix(ci): pin third-party actions to full commit SHAs (#387) #717

Workflow file for this run

# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Security Scan
on:
push:
branches: [main]
schedule:
- cron: '0 0 * * 0' # Weekly on Sunday at midnight
workflow_dispatch:
# Cause-B mitigation (#77): cancel superseded runs so stacked pushes
# to the same ref don't pile up identical jobs in the queue.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
scan:
uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@a030ef32c571b4aa22bbcd4a41acbdd9a801d366 # main 2026-07-07 (skip dispatch without VERISIMDB_PAT)
secrets:
VERISIMDB_PAT: ${{ secrets.VERISIMDB_PAT }}