Added blackduck.yml to scan the repo (#255)
This commit is contained in:
committed by
GitHub
parent
404f60d278
commit
5137e001ca
35
.github/workflows/blackduck.yml
vendored
35
.github/workflows/blackduck.yml
vendored
@@ -3,38 +3,11 @@ name: Blackduck
|
|||||||
on:
|
on:
|
||||||
schedule:
|
schedule:
|
||||||
# run scans twice a month
|
# run scans twice a month
|
||||||
- cron: "0 2 1,15 * *"
|
- cron: '0 2 1,15 * *'
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
blackduck:
|
blackduck:
|
||||||
runs-on: ubuntu-latest
|
name: Blackduck scan
|
||||||
steps:
|
uses: Fisker-Inc/github-actions/.github/workflows/blackduck.yml@main
|
||||||
- name: Checkout Code
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
|
|
||||||
- name: Use Node.js ${{ matrix.node-version }}
|
|
||||||
uses: actions/setup-node@v2
|
|
||||||
with:
|
with:
|
||||||
node-version: "16"
|
project: ota-admin-portal
|
||||||
cache: "npm"
|
|
||||||
- run: npm install
|
|
||||||
- run: npm run build
|
|
||||||
|
|
||||||
# ota-admin-portal
|
|
||||||
- name: Run Synopsys Detect - ota-admin-portal
|
|
||||||
uses: synopsys-sig/detect-action@v0.3.2
|
|
||||||
env:
|
|
||||||
DETECT_PROJECT_NAME: ota-admin-portal
|
|
||||||
DETECT_EXCLUDED_DIRECTORIES: node_modules
|
|
||||||
DETECT_PROJECT_VERSION_NAME: default
|
|
||||||
DETECT_NPM_INCLUDE_DEV_DEPENDENCIES: "FALSE"
|
|
||||||
# DETECT_DETECTOR_SEARCH_EXCLUSION_DEFAULTS: "true"
|
|
||||||
DETECT_DETECTOR_SEARCH_DEPTH: 0
|
|
||||||
DETECT_DETECTOR_SEARCH_CONTINUE: "true"
|
|
||||||
|
|
||||||
with:
|
|
||||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
detect-version: 7.9.0
|
|
||||||
blackduck-url: ${{ secrets.BLACKDUCK_URL }}
|
|
||||||
blackduck-api-token: ${{ secrets.BLACKDUCK_API_KEY }}
|
|
||||||
scan-mode: INTELLIGENT
|
|
||||||
|
|||||||
Reference in New Issue
Block a user