docs: add Signed commits section to CONTRIBUTING (#98) #142
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| name: Governance | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: [main, master] | |
| workflow_dispatch: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| actions: read # required by the reusable workflow (staleness check reads workflow runs) | |
| contents: read | |
| jobs: | |
| governance: | |
| uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 | |
| # Optional credentialed live-policy audit. governance-reusable@da2c748 | |
| # declares HYPATIA_SCAN_PAT (fine-grained PAT, Administration: read) as an | |
| # optional secret: without it the "Live Actions policy (credentialed | |
| # advisory)" job reports a notice instead of running; with it, the live | |
| # check actually executes. Passing an absent secret is a no-op. | |
| secrets: | |
| HYPATIA_SCAN_PAT: ${{ secrets.HYPATIA_SCAN_PAT }} |