File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ name : " OWASP Security Scans"
2+
13on :
24 push :
35 branches : [ "master" ]
4- pull_request :
5- branches : [ "master" ]
66
77 workflow_dispatch :
88
2929 - env :
3030 NVD_API_KEY :
3131 ${{ secrets.NVD_API_KEY }}
32+ OSSINDEX_USERNAME :
33+ ${{ secrets.OSSINDEX_USERNAME }}
34+ OSSINDEX_PASSWORD :
35+ ${{ secrets.OSSINDEX_PASSWORD }}
3236 run : |
33- mvn -DskipTests install -P OWASP_CHECK
37+ mvn -DskipTests install -P OWASP_CHECK -DossIndexUsername=${{ env.OSSINDEX_USERNAME }} -DossIndexPassword=${{ env.OSSINDEX_PASSWORD }}
3438
3539 - name : Upload SARIF file
3640 uses : github/codeql-action/upload-sarif@a4e1a019f5e24960714ff6296aee04b736cbc3cf # v3.29.6
Original file line number Diff line number Diff line change 9191 <plugin >
9292 <groupId >org.owasp</groupId >
9393 <artifactId >dependency-check-maven</artifactId >
94- <version >12.1.3 </version >
94+ <version >12.1.6 </version >
9595 <configuration >
9696 <nvdApiKeyEnvironmentVariable >NVD_API_KEY</nvdApiKeyEnvironmentVariable >
9797 <suppressionFiles >
You can’t perform that action at this time.
0 commit comments