-
Notifications
You must be signed in to change notification settings - Fork 14
74 lines (63 loc) · 2.33 KB
/
Copy pathdependency-scan.yml
File metadata and controls
74 lines (63 loc) · 2.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
name: Dependency vulnerability scan
# Checks the resolved runtime dependency tree of every SDK module against OSV (osv.dev), so a CVE
# published after a release is caught without waiting for the next build. OSV needs no API key.
# Fails on HIGH or CRITICAL; see .github/scripts/osv-scan.sh for the rule and osv-scanner.toml for
# accepted findings.
on:
schedule:
- cron: '23 5 * * 1'
workflow_dispatch:
push:
branches: [main]
paths:
- '**/pom.xml'
- '!integration-testing/**'
- 'osv-scanner.toml'
- '.github/scripts/osv-scan.sh'
- '.github/workflows/dependency-scan.yml'
permissions:
contents: read
concurrency:
group: dependency-scan-${{ github.ref }}
cancel-in-progress: true
env:
OSV_SCANNER_VERSION: '2.6.0'
OSV_SCANNER_SHA256: 'ca69b3d3cd08f889a49dc0a383122f71cc528b83803671df5fd874d97485b108'
jobs:
osv-scan:
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Set up JDK 17
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4
with:
java-version: '17'
distribution: 'temurin'
cache: maven
- name: Install osv-scanner
run: |
curl -sSfL -o "$RUNNER_TEMP/osv-scanner" \
"https://github.com/google/osv-scanner/releases/download/v${OSV_SCANNER_VERSION}/osv-scanner_linux_amd64"
echo "${OSV_SCANNER_SHA256} $RUNNER_TEMP/osv-scanner" | sha256sum --check --strict
chmod +x "$RUNNER_TEMP/osv-scanner"
echo "OSV_SCANNER=$RUNNER_TEMP/osv-scanner" >> "$GITHUB_ENV"
- name: Scan dependencies
run: .github/scripts/osv-scan.sh
- name: Upload SARIF to code scanning
if: always() && hashFiles('target/osv/results.sarif') != ''
uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: target/osv/results.sarif
category: osv-scanner
- name: Upload scan results
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: dependency-scan
path: target/osv/
if-no-files-found: ignore
retention-days: 30