ci: skip the OSV and image scans on scheduled fork runs

Both workflows run on a daily cron and neither checks the repository,
so every fork runs them too. They cannot pass there: osv-scan exits 1 on
whatever CVEs the fork's default branch happens to carry, and the six
image-scan jobs fail at the docker build. The result is two failed-run
emails a day to every person who forks litellm.

Fourteen workflows in this repo already guard against exactly this.
Adopt the same expression used by codeql, create-rc-branch and
weekly_load_anomaly:

    github.event_name != 'schedule' || github.repository == 'BerriAI/litellm'

image-scan keeps its existing fork-PR guard; the new clause is ANDed on,
matching the multi-clause form in e2e_record_replay.

Behaviour on BerriAI/litellm is unchanged for schedule, pull_request and
workflow_dispatch alike. Only scheduled runs on forks change, and manual
workflow_dispatch still works on a fork for anyone who wants to run the
scans there deliberately.
This commit is contained in:
Srivatsa03 2026-09-29 18:11:41 -05:00
parent e7460f1cff
commit 9a74796491
2 changed files with 19 additions and 12 deletions

View file

@ -41,8 +41,9 @@ jobs:
name: image-scan
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read
@ -102,8 +103,9 @@ jobs:
name: runtime-image
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read
@ -131,8 +133,9 @@ jobs:
name: migrations-image
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read
@ -162,8 +165,9 @@ jobs:
name: gateway-image
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read
@ -192,8 +196,9 @@ jobs:
name: ui-image
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read
@ -221,8 +226,9 @@ jobs:
name: backend-image
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository
(github.event_name != 'schedule' || github.repository == 'BerriAI/litellm') &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
timeout-minutes: 30
permissions:
contents: read

View file

@ -19,6 +19,7 @@ jobs:
osv-scan:
name: osv-scan
runs-on: ubuntu-latest
if: github.event_name != 'schedule' || github.repository == 'BerriAI/litellm'
timeout-minutes: 10
permissions:
contents: read