Skip to content

Commit b8dbfb5

Browse files
Merge pull request #65 from FHIR/do-20251001-fix-owasp-workflow
Fix OWASP workflow
2 parents 551768e + 6eb48be commit b8dbfb5

2 files changed

Lines changed: 8 additions & 4 deletions

File tree

.github/workflows/owasp.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
1+
name: "OWASP Security Scans"
2+
13
on:
24
push:
35
branches: [ "master" ]
4-
pull_request:
5-
branches: [ "master" ]
66

77
workflow_dispatch:
88

@@ -29,8 +29,12 @@ jobs:
2929
- env:
3030
NVD_API_KEY:
3131
${{ secrets.NVD_API_KEY }}
32+
OSSINDEX_USERNAME:
33+
${{ secrets.OSSINDEX_USERNAME }}
34+
OSSINDEX_PASSWORD:
35+
${{ secrets.OSSINDEX_PASSWORD }}
3236
run: |
33-
mvn -DskipTests install -P OWASP_CHECK
37+
mvn -DskipTests install -P OWASP_CHECK -DossIndexUsername=${{ env.OSSINDEX_USERNAME }} -DossIndexPassword=${{ env.OSSINDEX_PASSWORD }}
3438
3539
- name: Upload SARIF file
3640
uses: github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@
9191
<plugin>
9292
<groupId>org.owasp</groupId>
9393
<artifactId>dependency-check-maven</artifactId>
94-
<version>12.1.3</version>
94+
<version>12.1.6</version>
9595
<configuration>
9696
<nvdApiKeyEnvironmentVariable>NVD_API_KEY</nvdApiKeyEnvironmentVariable>
9797
<suppressionFiles>

0 commit comments

Comments
 (0)