refactor: drop em dashes from .asf.yaml and CI workflow comments #3848
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Security Checks | |
| on: | |
| push: | |
| pull_request: | |
| types: [opened, synchronize, reopened, ready_for_review] | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - python-version: 3.13 | |
| toxenv: safety | |
| - python-version: 3.13 | |
| toxenv: bandit | |
| steps: | |
| - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 | |
| with: | |
| submodules: recursive | |
| - name: Setup python | |
| uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install dependencies | |
| run: | | |
| pip install --upgrade virtualenv | |
| pip install tox | |
| - name: Run security checks | |
| env: | |
| TOXENV: ${{ matrix.toxenv }} | |
| run: tox | |
| # Stable aggregate context for the .asf.yaml branch protection on master. | |
| # See the matching ci-required job in quality.yml for why the generated | |
| # "build (<python>, <toxenv>)" names must not be required directly. | |
| security-required: | |
| # always() so a failed matrix still runs this job: a skipped job counts as a | |
| # satisfied required check, which would quietly disable the protection. | |
| if: always() | |
| needs: build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Verify every matrix leg passed | |
| run: | | |
| echo "build result: ${{ needs.build.result }}" | |
| [ "${{ needs.build.result }}" = "success" ] |