ci: declare workflow-level contents: read on go/python/java/typescript test workflows#38623
ci: declare workflow-level contents: read on go/python/java/typescript test workflows#38623arpitjain099 wants to merge 1 commit into
contents: read on go/python/java/typescript test workflows#38623Conversation
…t test workflows Four per-language test workflows just run their language test suites; no GitHub API writes from the workflows themselves. Post-CVE-2025-30066 hardening pattern. yaml.safe_load validated. Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
|
Checks are failing. Will not request review until checks are succeeding. If you'd like to override that behavior, comment |
|
Heads-up on the failing checks:
That's an Apache enterprise Actions allowlist policy, not anything my PR changed. My diff only adds a Happy to close if the test-workflows are the wrong target, or to leave it for whenever the enterprise allowlist gets updated. Let me know. |
Four per-language test workflows (
go_tests,python_tests,java_tests,typescript_tests) just run their language test suites. No GitHub API writes from the workflows themselves.Same post-CVE-2025-30066 (
tj-actions/changed-files) hardening pattern. YAML validated locally.