Update Snyk Workflow to target other branches (#20602)

Closes #20364

Co-authored-by: Stian Thorgersen <stianst@gmail.com>
This commit is contained in:
Bruno Oliveira da Silva 2023-06-01 04:03:12 -03:00 committed by GitHub
parent f546e28306
commit 24bc76b3f3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -1,8 +1,6 @@
name: Snyk
on:
schedule:
- cron: 0 0 * * *
on:
workflow_dispatch:
defaults:
@ -16,20 +14,20 @@ jobs:
if: github.repository == 'keycloak/keycloak'
steps:
- uses: actions/checkout@v3
- name: Build Keycloak
uses: ./.github/actions/build-keycloak
- uses: snyk/actions/setup@master
- name: Check for vulnerabilities in Quarkus
run: snyk test --policy-path=${GITHUB_WORKSPACE}/.github/snyk/.snyk --all-projects --prune-repeated-subdependencies --exclude=tests --sarif-file-output=quarkus-report.sarif quarkus
run: snyk test --policy-path=${GITHUB_WORKSPACE}/.github/snyk/.snyk --all-projects --prune-repeated-subdependencies --exclude=tests --sarif-file-output=quarkus-report.sarif quarkus/deployment
continue-on-error: true
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
- name: Upload Quarkus scanner results to GitHub
uses: github/codeql-action/upload-sarif@v2.2.12
uses: github/codeql-action/upload-sarif@v2.3.3
with:
sarif_file: quarkus-report.sarif
category: snyk-quarkus-report
@ -43,7 +41,7 @@ jobs:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
- name: Upload Operator scanner results to GitHub
uses: github/codeql-action/upload-sarif@v2.2.12
uses: github/codeql-action/upload-sarif@v2.3.3
with:
sarif_file: operator-report.sarif
category: snyk-operator-report