Bump aquasecurity/trivy-action from 314ff8b43182423b84c50b1670b0e10f858f2d98 to bfa4b33a029b9aa80ddb784b45574c30e072c59e in the github-actions group #540
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: "CLA Assistant" | |
| on: | |
| issue_comment: | |
| types: [created] | |
| pull_request_target: | |
| types: [opened,closed,synchronize] | |
| jobs: | |
| CLAssistant: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: "CLA Assistant" | |
| if: (github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target' | |
| uses: contributor-assistant/github-action@v2.6.1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # the below token should have repo scope and must be manually added by you in the repository's secret | |
| PERSONAL_ACCESS_TOKEN : ${{ secrets.CDRCOMMUNITY_GITHUB_TOKEN }} | |
| with: | |
| remote-organization-name: 'coder' | |
| remote-repository-name: 'cla' | |
| path-to-signatures: 'v2022-09-04/signatures.json' | |
| path-to-document: 'https://github.com/coder/cla/blob/main/README.md' | |
| # branch should not be protected | |
| branch: 'main' | |
| allowlist: dependabot* |