Skip to content

feat(cli): add offline deploy with --upload-url for custom S3 #336

feat(cli): add offline deploy with --upload-url for custom S3

feat(cli): add offline deploy with --upload-url for custom S3 #336

Workflow file for this run

name: OSV-Scanner PR Scan
on:
pull_request:
merge_group:
permissions:
actions: read
contents: read
security-events: write
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
scan-pr:
name: OSV Scanner PR
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
fetch-depth: 0
persist-credentials: false
- name: Checkout target branch
env:
BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha }}
run: |
git checkout "$BASE_SHA"
git submodule update --recursive
- name: Run scanner on existing code
uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2
continue-on-error: true
with:
scan-args: |-
--format=json
--output=old-results.json
--recursive
./
- name: Checkout current branch
run: |
git checkout -f "$GITHUB_SHA"
git submodule update --recursive
- name: Run scanner on new code
uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2
continue-on-error: true
with:
scan-args: |-
--format=json
--output=new-results.json
--recursive
./
- name: Compare scanner results
id: compare
uses: google/osv-scanner-action/osv-reporter-action@9a498708959aeaef5ef730655706c5a1df1edbc2
continue-on-error: true
with:
scan-args: |-
--output=results.sarif
--old=old-results.json
--new=new-results.json
--gh-annotations=true
--fail-on-vuln=true
- name: Upload to code scanning
if: ${{ !cancelled() && hashFiles('results.sarif') != '' }}
uses: github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89
with:
sarif_file: results.sarif
- name: Fail on newly introduced vulnerabilities
if: ${{ steps.compare.outcome == 'failure' }}
run: |
echo "::error::OSV-Scanner found newly introduced vulnerabilities."
exit 1