12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849 |
- # the benefit of this over dependabot is that this also analyzes transitive dependencies
- # while dependabot (at least currently) only analyzes top-level dependencies
- name: OWASP dependency check (daily)
- on:
- schedule:
- # daily at 1:30 UTC
- - cron: "30 1 * * *"
- workflow_dispatch:
- jobs:
- analyze:
- runs-on: ubuntu-latest
- steps:
- - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- - name: Free disk space
- run: .github/scripts/gha-free-disk-space.sh
- - name: Set up JDK for running Gradle
- uses: actions/setup-java@99b8673ff64fbf99d8d325f52d9a5bdedb8483e9 # v4.2.1
- with:
- distribution: temurin
- java-version-file: .java-version
- - name: Increase gradle daemon heap size
- run: |
- sed -i "s/org.gradle.jvmargs=/org.gradle.jvmargs=-Xmx3g /" gradle.properties
- - uses: gradle/actions/setup-gradle@d9336dac04dea2507a617466bc058a3def92b18b # v3.4.0
- - run: ./gradlew :javaagent:dependencyCheckAnalyze
- env:
- NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
- - name: Upload report
- if: always()
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
- with:
- path: javaagent/build/reports
- workflow-notification:
- needs:
- - analyze
- if: always()
- uses: ./.github/workflows/reusable-workflow-notification.yml
- with:
- success: ${{ needs.analyze.result == 'success' }}
|