Skip to content
Draft
Show file tree
Hide file tree
Changes from 6 commits
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
9243d08
schedule actionlint at 04:05 monday-friday
ejcsid Jul 15, 2026
16d6533
build.yml runs at 04:10, Monday through Friday and on pushes to sps-t…
ejcsid Jul 15, 2026
f13953c
codeql.ml runs at 04:15, Monday through Friday and an pushes to sps-t…
ejcsid Jul 15, 2026
90bf9c9
dependency-review.yml runs at 04:20, Monday through Friday
ejcsid Jul 15, 2026
0ff02ce
timezone: "Europe/Berlin"
ejcsid Jul 15, 2026
2c221c7
Add schedule triggers for all workflows
ejcsid Jul 15, 2026
7343d5b
Handle failures (send notifications to webex)
ejcsid Jul 16, 2026
714c3ee
Changed ReadMe.md for sps-test intention and usage.
ejcsid Jul 16, 2026
c57702e
Fixed typos
ejcsid Jul 16, 2026
405cdc5
schedule npm for timezone Europe/Berlin, added defaults for inputs in…
ejcsid Jul 16, 2026
3d616c7
chore(frontend): bump version to v0.0.1
invalid-email-address Jul 17, 2026
0ce8a3a
Merge pull request #5 from it-at-m/release-frontend-v0.0.1
ejcsid Jul 17, 2026
04a7b2f
Added env vars as default for input vars if running scheduled
ejcsid Jul 17, 2026
5134e50
Merge branch 'sps-test-main' of https://github.com/it-at-m/sps-test i…
ejcsid Jul 17, 2026
1298741
schedule not possible as it has to run on a pull_request.
ejcsid Jul 17, 2026
212ae0f
default values for scheduled trigger
ejcsid Jul 17, 2026
e2528ef
added codeql-origin.yml
ejcsid Jul 17, 2026
9fab506
env DEFAULT_APP_PATH: "backend"
ejcsid Jul 20, 2026
c7f4d61
Delete .github/workflows/codeql.yml
ejcsid Jul 20, 2026
95c7d3a
Create codeql.yml
ejcsid Jul 20, 2026
87d7fc5
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
794e8da
Create codeql-origin.yml
ejcsid Jul 20, 2026
d37040e
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
4c2e2e4
Delete .github/workflows/codeql.yml
ejcsid Jul 20, 2026
334202c
Create codeql.yml
ejcsid Jul 20, 2026
45bb3ab
Create codeql-origin.yml
ejcsid Jul 20, 2026
50b3d24
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
098418c
Create codeql-origin.yml
ejcsid Jul 20, 2026
fbaf98d
Delete .github/workflows/codeql-origin.yml
ejcsid Jul 20, 2026
2c40547
Update actionlint.yml
hupling Jul 21, 2026
9c6282d
Update Webex notification message format
hupling Jul 21, 2026
db7c4e8
Update Webex notification message format
hupling Jul 21, 2026
b9ecf23
Update actionlint.yml
hupling Jul 21, 2026
2165f32
Update build.yml
hupling Jul 21, 2026
9b5cfa4
Update dependency-review.yml
hupling Jul 21, 2026
115aaef
Update deploy-docs.yml
hupling Jul 21, 2026
b3134f2
Update Webex notification message format
hupling Jul 21, 2026
9912d36
Update pr-labeler.yml
hupling Jul 21, 2026
0aee285
Update Webex notification message format
hupling Jul 21, 2026
5d73a4a
Update Webex notification message format
hupling Jul 21, 2026
b2e0f84
Update trivy.yml
hupling Jul 21, 2026
700cfde
Apply suggestions from code review
hupling Jul 21, 2026
d18a557
Update build.yml
hupling Jul 21, 2026
69f8508
Update build.yml
hupling Jul 21, 2026
64e834a
Update build.yml
hupling Jul 21, 2026
e5d560b
Update actionlint.yml
hupling Jul 21, 2026
95a9fb0
Update CodeQL workflow condition for failure
hupling Jul 21, 2026
dbe7cef
Update dependency-review.yml
hupling Jul 21, 2026
f09a670
Update deploy-docs.yml
hupling Jul 21, 2026
b4edbc2
Update dockercompose-healthcheck.yml
hupling Jul 21, 2026
1d858ab
Update failure condition for handlefailure job
hupling Jul 21, 2026
94fd488
Update release-maven.yml
hupling Jul 21, 2026
a6cd790
Update release-npm.yml
hupling Jul 21, 2026
67d9124
Update trivy.yml
hupling Jul 21, 2026
0505933
Merge pull request #8 from it-at-m/change-webex
hupling Jul 21, 2026
aecbe90
Merge branch 'main' into sps-test-main
ejcsid Jul 21, 2026
6b412c8
Add permissions block to handlefailure-Job in workflows
ejcsid Jul 21, 2026
9cf11cc
add env-default-values to lhm_actions actions calls
ejcsid Jul 22, 2026
cc97034
add env-default values to lhm_actions actions calls
ejcsid Jul 22, 2026
3922de2
Apply suggestions from code review
ejcsid Jul 22, 2026
de4cd2b
Apply suggestion from @ejcsid
ejcsid Jul 22, 2026
bac5839
Apply suggestion from @ejcsid
ejcsid Jul 22, 2026
9523cf0
fix(workflows): Add missing env-defaults to action calls
ejcsid Jul 23, 2026
704820f
[maven-release-plugin] prepare release refarch-backend-0.0.3
invalid-email-address Jul 24, 2026
6931ccf
[maven-release-plugin] prepare for next development iteration
invalid-email-address Jul 24, 2026
a109776
Merge pull request #14 from it-at-m/release-backend-0.0.4-SNAPSHOT
ejcsid Jul 24, 2026
6f4970f
chore(workflows): removing schedule block from release-maven
ejcsid Jul 24, 2026
5c0e8ac
chore(workflows): removing schedule block from release-maven
ejcsid Jul 24, 2026
ab49d36
Merge branch 'main' into sps-test-main
hupling Jul 29, 2026
d3114d3
Update build.yml
hupling Jul 29, 2026
b878258
Update release-maven.yml
hupling Jul 29, 2026
e7d9f80
Update dependency in handlefailure job
hupling Jul 29, 2026
887fec6
Merge pull request #18 from it-at-m/fix-lint
hupling Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/actionlint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: actionlint

on:
pull_request:
schedule:
- cron: "5 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
actionlint:
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,10 @@ on:
pull_request:
push:
branches:
- "main"
- "sps-test-main"
schedule:
- cron: "10 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
# JOB to run change detection
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,10 @@ on:
pull_request:
push:
branches:
- "main" # Runs on main in order to keep the regular scanning by GitHub working
- "sps-test-main"
schedule:
- cron: "15 4 * * 1-5"
timezone: "Europe/Berlin"

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: dependency-review

on:
pull_request:
schedule:
- cron: "20 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
dependency-review:
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/deploy-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,14 +5,17 @@ on:
# Runs on pushes to any branch when changes are made to docs or workflow
push:
branches:
- main
- sps-test-main
paths:
- "docs/**"
- ".github/workflows/deploy-docs.yml"
Comment on lines +8 to 11

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Do not authorize Pages deployment from the test branch unintentionally.

Pushes to sps-test-main now reach a job with pages: write and id-token: write permissions, while Line 29 still states that deployment is restricted to main. Keep deployment restricted to the production branch, or add an explicit environment/condition for test-branch deployments.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/deploy-docs.yml around lines 8 - 11, Update the workflow
trigger and deployment authorization around the production-branch restriction so
pushes to sps-test-main cannot run the Pages deployment job with pages: write or
id-token: write permissions. Keep deployment limited to main, or add an explicit
environment and condition that prevents unintended test-branch deployments.

pull_request:
paths:
- "docs/**"
- ".github/workflows/deploy-docs.yml"
schedule:
- cron: "25 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
deploy-docs:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/dockercompose-healthcheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: dockercompose-healthcheck

on:
pull_request:
schedule:
- cron: "30 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
dockercompose-healthcheck:
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/pr-labeler.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,10 @@
# Workflow to assign appropriate labels to PRs
name: pr-labeler
on:
- pull_request_target
pull_request_target:
schedule:
- cron: "35 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
pr-labeler:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/release-maven.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@ on:
options: # Add or modify paths according to your project structure
- backend
- eai
schedule:
- cron: "40 4 * * 1-5"
timezone: "Europe/Berlin"

jobs:
release-maven-artifact:
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/release-npm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,10 @@ on:
options: # Add or modify paths according to your project structure
- frontend
- webcomponent

schedule:
- cron: '30 5 * * 1-5'
timezone: "America/New_York"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

sed -n '1,120p' .github/workflows/release-npm.yml && printf '\n---\n' && rg -n "Europe/Berlin|America/New_York|timezone:" .github/workflows . -g '!**/node_modules/**' -g '!**/dist/**' -g '!**/build/**'

Repository: it-at-m/sps-test

Length of output: 3988


Use the agreed schedule timezone. .github/workflows/release-npm.yml still uses America/New_York for the cron schedule; switch it to Europe/Berlin to match the other scheduled workflows.

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 4-25: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-npm.yml around lines 23 - 25, Update the scheduled
workflow’s cron configuration to use the agreed Europe/Berlin timezone instead
of America/New_York, leaving the existing cron expression unchanged.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

sed -n '1,220p' .github/workflows/release-npm.yml

Repository: it-at-m/sps-test

Length of output: 3174


🏁 Script executed:

rg -n "Europe/Berlin|America/New_York|timezone|release-npm" .github README* docs* . 2>/dev/null

Repository: it-at-m/sps-test

Length of output: 2044


🌐 Web query:

GitHub Actions schedule timezone field supported inputs context schedule event workflow_dispatch docs

💡 Result:

GitHub Actions supports a timezone field within the schedule event trigger, allowing workflows to run based on a specified IANA timezone rather than defaulting to UTC [1][2][3]. Schedule Event Timezone Support: - You can specify a timezone using an IANA timezone string (e.g., "America/New_York") alongside your POSIX cron expression [1][2]. - This feature allows for timezone-aware scheduling, including proper handling of daylight saving time transitions [1][2]. - Example configuration: on: schedule: - cron: '30 5 * * 1-5' timezone: "America/New_York" Workflow_dispatch Contexts: - Workflows triggered by workflow_dispatch can access inputs provided during the trigger event [4][5]. - The recommended way to access these values is through the inputs context (e.g., ${{ inputs.input_name }}) [6][4][5]. - For backward compatibility, these inputs are also available within the github.event.inputs context [5]. Additional Context: - The timezone field support for scheduled workflows was introduced in March 2026 [3][7]. - The schedule event triggers workflows only if the workflow file exists on the default branch [2][8]. - Scheduled workflows may be delayed during periods of high system load [2]. - You can define up to 25 inputs for a workflow_dispatch event [8].

Citations:


🏁 Script executed:

rg -n "use-pr|release-version|app-path|workflow_dispatch|schedule" .github/workflows . 2>/dev/null

Repository: it-at-m/sps-test

Length of output: 3101


🌐 Web query:

GitHub Actions schedule event inputs context empty default workflow_dispatch only docs

💡 Result:

In GitHub Actions, the inputs context and the github.event.inputs context are specifically designed for manually triggered workflows using the workflow_dispatch event [1][2][3]. When a workflow is triggered by a schedule event, it does not support the definition or receipt of inputs in the same way as workflow_dispatch [4][5]. Consequently, if a workflow is triggered by a schedule event, the inputs context will be empty [4]. Scheduled workflows are triggered automatically based on a cron schedule rather than by a user providing input values [2]. If you need to trigger a workflow both on a schedule and manually with inputs, the standard practice is to separate your logic [4][6]: 1. Create a primary workflow (or a reusable workflow using workflow_call) that contains the core logic and accepts the required inputs [6]. 2. Create a separate workflow_dispatch trigger that calls the primary workflow with specific inputs [4][6]. 3. Create a separate schedule trigger that calls the same primary workflow, passing in static or default values for the inputs [4][6].

Citations:


Guard the cron trigger or pass fixed values. .github/workflows/release-npm.yml schedules the release without defining app-path or release-version, so ${{ inputs.app-path }} and ${{ inputs.release-version }} are empty on scheduled runs while use-pr still executes. Either gate this job to workflow_dispatch or supply explicit scheduled values.

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 4-25: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release-npm.yml around lines 23 - 25, Update the scheduled
trigger handling in the release workflow so the release job does not run with
empty app-path and release-version inputs. Either restrict the job to
workflow_dispatch runs using its condition, or provide explicit fixed values for
scheduled executions while preserving the existing manual-input behavior.


jobs:
release-npm-artifact:
runs-on: ubuntu-latest
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/trivy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ on:
pull_request:
schedule:
- cron: '0 3 * * *' # Daily at 03:00 UTC
timezone: "Europe/Berlin"

jobs:
trivy:
Expand Down
Loading