Skip to content

Init change for scaning dependency vulnerability #6

Init change for scaning dependency vulnerability

Init change for scaning dependency vulnerability #6

name: "Dependency Review"
on:
pull_request:
branches:
- "master"
- "al2023"
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/dependency-review-action@v4
gosec:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: securego/gosec@master
with:
args:
- -exclude=G101,G103,G204

Check failure on line 22 in .github/workflows/dependency-review.yaml

View workflow run for this annotation

GitHub Actions / Dependency Review

Invalid workflow file

The workflow is not valid. .github/workflows/dependency-review.yaml (Line: 22, Col: 13): A sequence was not expected
- nodeadm/...
govulncheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: golang/govulncheck-action@v1
with:
go-version-input: 1.21.6
work-dir: ./nodeadm
go-version-file: nodeadm/go.mod
cache: false
repo-checkout: false