Skip to content

Add Macaron GitHub Action Check#747

Open
anshisinghh wants to merge 4 commits intomasterfrom
add-macaron-github-actions
Open

Add Macaron GitHub Action Check#747
anshisinghh wants to merge 4 commits intomasterfrom
add-macaron-github-actions

Conversation

@anshisinghh
Copy link
Copy Markdown
Member

@anshisinghh anshisinghh commented Apr 17, 2026

Summary

Add Macaron policy verification for GitHub Actions using the check-github-actions policy.

What this change does

  • Adds a dedicated workflow for Macaron verification
  • Checks workflow definitions and local composite actions
  • Uses pinned actions and disables persisted checkout credentials

Why this is required

This helps detect unsafe or vulnerable GitHub Actions usage and reduces risk from software supply chain attacks targeting CI/CD pipelines.

Required follow-up

  • Enable Macaron policy verification as a required status check for protected branches
  • Resolve any policy findings before merge if applicable

@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant