Skip to content

Github action

Github action #40

Workflow file for this run

# Copyright 2023 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
name: osv-scanner
on:
push:
branches: [ main ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ main ]
merge_group:
branches: [ main ]
# Declare default permissions as read only.
permissions: read-all
jobs:
scan-pr-attempt:
uses: "./.github/workflows/osv-scanner-pr.yml"
# scan:
# name: OSV-Scanner scan
# runs-on: ubuntu-latest
# permissions:
# # Needed to upload the results to code-scanning dashboard.
# security-events: write
# # Needed to publish results and get a badge (see publish_results below).
# id-token: write
# # Uncomment the permissions below if installing in a private repository.
# # contents: read
# # actions: read
# steps:
# - name: "Checkout code"
# uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
# with:
# persist-credentials: false
# - name: "Run scanner"
# uses: ./ # Uses ./action.yaml
# with:
# results-format: sarif
# results-file: results.sarif
# to-scan: |-
# ./
# ./cmd/osv-scanner/fixtures/locks-many/
# # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# # format to the repository Actions tab.
# - name: "Upload artifact"
# if: '!cancelled()'
# uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
# with:
# name: SARIF file
# path: results.sarif
# retention-days: 5
# # Upload the results to GitHub's code scanning dashboard.
# - name: "Upload to code-scanning"
# if: '!cancelled()'
# uses: github/codeql-action/upload-sarif@6c089f53dd51dc3fc7e599c3cb5356453a52ca9e # v2.20.0
# with:
# sarif_file: results.sarif