Skip to content

Add gosec

Add gosec #28

name: "Dependency Review"
on:
pull_request:
branches:
- "master"
- "al2023"
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/dependency-review-action@v4
gosec:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: securego/gosec@master
with:
args: -exclude=G101,G103,G204 ./...
working-directory: nodeadm

Check failure on line 22 in .github/workflows/dependency-review.yaml

View workflow run for this annotation

GitHub Actions / Dependency Review

Invalid workflow file

The workflow is not valid. .github/workflows/dependency-review.yaml (Line: 22, Col: 9): Unexpected value 'working-directory'
govulncheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: golang/govulncheck-action@v1
with:
go-version-input: 1.21.6
work-dir: ./nodeadm
go-version-file: nodeadm/go.mod
cache: false
repo-checkout: false