Skip to content

feat: add a workflow to run Macaron for supply chain security detection#1099

Merged
behnazh merged 1 commit intomainfrom
behnazh/add-macaron-check
Apr 7, 2026
Merged

feat: add a workflow to run Macaron for supply chain security detection#1099
behnazh merged 1 commit intomainfrom
behnazh/add-macaron-check

Conversation

@behnazh
Copy link
Copy Markdown
Collaborator

@behnazh behnazh commented Feb 25, 2026

Summary

This PR adds a new workflow to run Macaron for supply chain security detection.

It enables the check-github-actions policy to analyze GitHub workflows for insecure patterns and potential risks. When issues are detected, detailed findings and remediation suggestions are included in the workflow summary. Full reports are also uploaded as workflow artifacts for further review.

For more details, see: https://oracle.github.io/macaron/pages/macaron_action.html

@behnazh behnazh force-pushed the behnazh/add-macaron-check branch 2 times, most recently from 4a567e3 to 881fb84 Compare March 31, 2026 09:17
@behnazh behnazh force-pushed the behnazh/add-macaron-check branch from 881fb84 to ededb89 Compare March 31, 2026 09:54
@jenstroeger jenstroeger marked this pull request as ready for review April 7, 2026 09:21
@jenstroeger jenstroeger self-requested a review as a code owner April 7, 2026 09:21
Copy link
Copy Markdown
Owner

@jenstroeger jenstroeger left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very excited to Macaron integrated!

@behnazh behnazh merged commit bfdeb62 into main Apr 7, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants