Skip to content
This repository was archived by the owner on Feb 25, 2025. It is now read-only.

Conversation

@sealesj
Copy link
Contributor

@sealesj sealesj commented Jan 16, 2024

This change simplifies the osv-scanner workflow by extracting dependencies from the DEPS file and then finding their common ancestor commit with upstream in one script.

Fixes: flutter/flutter#141184

If you had to change anything in the flutter/tests repo, include a link to the migration guide as per the breaking change policy.

Pre-launch Checklist

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • I read the Tree Hygiene wiki page, which explains my responsibilities.
  • I read and followed the Flutter Style Guide and the C++, Objective-C, Java style guides.
  • I listed at least one issue that this PR fixes in the description above.
  • I added new tests to check the change I am making or feature I am adding, or the PR is test-exempt. See testing the engine for instructions on writing and running engine tests.
  • I updated/added relevant documentation (doc comments with ///).
  • I signed the CLA.
  • All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel on Discord.

@sealesj
Copy link
Contributor Author

sealesj commented Jan 17, 2024

It looks like this update on the osv-scanner side broke our workflow since v3 upload actions cannot be paired with v4 download actions.

@sealesj sealesj marked this pull request as ready for review January 17, 2024 21:37
@sealesj sealesj added the autosubmit Merge PR when tree becomes green via auto submit App label Jan 18, 2024
@auto-submit auto-submit bot merged commit 75400c4 into flutter:main Jan 18, 2024
@sealesj sealesj deleted the simplify_osv_scanner branch January 18, 2024 18:49
engine-flutter-autoroll added a commit to engine-flutter-autoroll/flutter that referenced this pull request Jan 18, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

autosubmit Merge PR when tree becomes green via auto submit App vulnerability scan

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Simplify engine osv-scanner workflow

2 participants