Repository navigation
feat(cli): add offline deploy with --upload-url for custom S3 #336
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: OSV-Scanner PR Scan | |
| on: | |
| pull_request: | |
| merge_group: | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| env: | |
| FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true | |
| jobs: | |
| scan-pr: | |
| name: OSV Scanner PR | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Checkout target branch | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha }} | |
| run: | | |
| git checkout "$BASE_SHA" | |
| git submodule update --recursive | |
| - name: Run scanner on existing code | |
| uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 | |
| continue-on-error: true | |
| with: | |
| scan-args: |- | |
| --format=json | |
| --output=old-results.json | |
| --recursive | |
| ./ | |
| - name: Checkout current branch | |
| run: | | |
| git checkout -f "$GITHUB_SHA" | |
| git submodule update --recursive | |
| - name: Run scanner on new code | |
| uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 | |
| continue-on-error: true | |
| with: | |
| scan-args: |- | |
| --format=json | |
| --output=new-results.json | |
| --recursive | |
| ./ | |
| - name: Compare scanner results | |
| id: compare | |
| uses: google/osv-scanner-action/osv-reporter-action@9a498708959aeaef5ef730655706c5a1df1edbc2 | |
| continue-on-error: true | |
| with: | |
| scan-args: |- | |
| --output=results.sarif | |
| --old=old-results.json | |
| --new=new-results.json | |
| --gh-annotations=true | |
| --fail-on-vuln=true | |
| - name: Upload to code scanning | |
| if: ${{ !cancelled() && hashFiles('results.sarif') != '' }} | |
| uses: github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89 | |
| with: | |
| sarif_file: results.sarif | |
| - name: Fail on newly introduced vulnerabilities | |
| if: ${{ steps.compare.outcome == 'failure' }} | |
| run: | | |
| echo "::error::OSV-Scanner found newly introduced vulnerabilities." | |
| exit 1 |