diff --git a/.github/workflows/registry-scanner.yaml b/.github/workflows/registry-scanner.yaml index 08e04680..7ff07b00 100644 --- a/.github/workflows/registry-scanner.yaml +++ b/.github/workflows/registry-scanner.yaml @@ -14,7 +14,7 @@ on: permissions: contents: read - + jobs: scan_job: name: Scanner Registry Action @@ -29,7 +29,7 @@ jobs: - name: Checkout uses: actions/checkout@ee0669bd1cc54295c223e0bb666b733df41de1c5 # v2.7.0 - name: Scan Registry - uses: boostsecurityio/scanner-registry-action@bcec6e2aedd41802de36511587d46e2eb47e8805 # v1.5.3 + uses: boostsecurityio/scanner-registry-action@7c3690aed2453f790be130a209d644c41b333fb7 # v1.5.4 with: api_endpoint: ${{ vars.BOOST_API_ENDPOINT }} api_token: ${{ secrets.BOOST_SYSTEM_API_KEY_REGISTRY }} diff --git a/scanners/boostsecurityio/boost-sca/module.yaml b/scanners/boostsecurityio/boost-sca/module.yaml index 9a59ea00..7ee8f5f1 100644 --- a/scanners/boostsecurityio/boost-sca/module.yaml +++ b/scanners/boostsecurityio/boost-sca/module.yaml @@ -5,6 +5,7 @@ name: BoostSecurity SCA namespace: boostsecurityio/boost-sca scan_types: - sca + - license config: require_full_repo: true diff --git a/scanners/boostsecurityio/boost-sca/rules.yaml b/scanners/boostsecurityio/boost-sca/rules.yaml index 629f9ed2..b933e734 100644 --- a/scanners/boostsecurityio/boost-sca/rules.yaml +++ b/scanners/boostsecurityio/boost-sca/rules.yaml @@ -1,5 +1,6 @@ import: - boostsecurityio/sca-cve + - boostsecurityio/oss-license rules: dependency-with-malicious-behaviour: