From f21332f07384cf1582be2b96e7e64dbc18fba0b8 Mon Sep 17 00:00:00 2001 From: mromano3 Date: Tue, 28 Jul 2026 22:38:29 -0700 Subject: [PATCH] ci(security): include photon sidecar + whatsapp bridge lockfiles in OSV scan Surgical reapply of PR #46747 by @tank321 onto the current reusable-workflow form of osv-scanner.yml (the original targeted the old direct-action layout). Fixes #46738. --- .github/workflows/osv-scanner.yml | 4 +++- contributors/emails/mromano3@ad.engr.wisc.edu | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) create mode 100644 contributors/emails/mromano3@ad.engr.wisc.edu diff --git a/.github/workflows/osv-scanner.yml b/.github/workflows/osv-scanner.yml index 455ede33dd..c3aaa50a7b 100644 --- a/.github/workflows/osv-scanner.yml +++ b/.github/workflows/osv-scanner.yml @@ -43,11 +43,13 @@ jobs: uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8 with: # Scan explicit lockfiles rather than recursing, so we only look at - # the three sources of truth and skip vendored / test / worktree dirs. + # the five sources of truth and skip vendored / test / worktree dirs. scan-args: |- --lockfile=uv.lock --lockfile=package-lock.json --lockfile=website/package-lock.json + --lockfile=plugins/platforms/photon/sidecar/package-lock.json + --lockfile=scripts/whatsapp-bridge/package-lock.json # The upstream reusable workflow uploads this exact file under its # fixed artifact name, which the wrapper downloads below. results-file-name: osv-results.sarif diff --git a/contributors/emails/mromano3@ad.engr.wisc.edu b/contributors/emails/mromano3@ad.engr.wisc.edu new file mode 100644 index 0000000000..9806e57b04 --- /dev/null +++ b/contributors/emails/mromano3@ad.engr.wisc.edu @@ -0,0 +1 @@ +tank321