From 24bdb8bdf21358e7b505f0d2f9f994c8ca2f1e38 Mon Sep 17 00:00:00 2001 From: Liam Schneider <57731583+liamschn@users.noreply.github.com> Date: Wed, 19 Jun 2024 15:32:48 -0600 Subject: [PATCH] Update safety.yml trying to solve issues with safety cli not running --- .github/workflows/safety.yml | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/workflows/safety.yml b/.github/workflows/safety.yml index 663a0374..42e2c90f 100644 --- a/.github/workflows/safety.yml +++ b/.github/workflows/safety.yml @@ -1,7 +1,7 @@ name: safety - Python Dependency Check on: - pull_request: + pull_request_target: branches: - main push: @@ -54,9 +54,14 @@ jobs: if: steps.cached-poetry-no-dev-dependencies.outputs.cache-hit != 'true' run: poetry install --only main --no-root #---------------------------------------------- - # Run Safety check + # Run Safety scan #---------------------------------------------- - - name: Safety check + - name: Safety scan + env: + API_KEY: ${{secrets.SAFETY_API_KEY}} + TEST_VAR: ${{secrets.TEST_SECRET}} run: | + echo "test variable:" + echo "$TEST_VAR" poetry run pip install safety - poetry run safety check + poetry run safety --key "$API_KEY" --stage cicd scan