Skip to content

Add Macaron GitHub Action Check | Legacy Java#748

Open
anshisinghh wants to merge 3 commits intolegacy/v2/masterfrom
update-github-workflows-legacy
Open

Add Macaron GitHub Action Check | Legacy Java#748
anshisinghh wants to merge 3 commits intolegacy/v2/masterfrom
update-github-workflows-legacy

Conversation

@anshisinghh
Copy link
Copy Markdown
Member

@anshisinghh anshisinghh commented Apr 17, 2026

Updated releasepublished.yml to Migrate Maven Central publishing to new portal APIs

Summary

Add Macaron policy verification for GitHub Actions using the check-github-actions policy.

What this change does

  • Adds a dedicated workflow for Macaron verification
  • Checks workflow definitions and local composite actions
  • Uses pinned actions and disables persisted checkout credentials

Why this is required

This helps detect unsafe or vulnerable GitHub Actions usage and reduces risk from software supply chain attacks targeting CI/CD pipelines.

Required follow-up

  • Enable Macaron policy verification as a required status check for protected branches
  • Resolve any policy findings before merge if applicable

@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Apr 17, 2026
@anshisinghh anshisinghh changed the title Update releasepublished.yml and Add Macaron GitHub Action Check Update releasepublished.yml and Add Macaron GitHub Action Check | Legacy Java Apr 17, 2026
@anshisinghh anshisinghh changed the title Update releasepublished.yml and Add Macaron GitHub Action Check | Legacy Java Add Macaron GitHub Action Check | Legacy Java Apr 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant