Skip to content

Commit

Permalink
Add snyk to GHA
Browse files Browse the repository at this point in the history
  • Loading branch information
Mahoney committed Sep 13, 2024
1 parent 0fdbfc4 commit 89fad75
Show file tree
Hide file tree
Showing 2 changed files with 31 additions and 2 deletions.
19 changes: 17 additions & 2 deletions .github/workflows/gradle.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,12 +21,12 @@ jobs:
JDK_VERSION: ${{ matrix.jdk }}

steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Set up JDK
uses: actions/setup-java@v2
uses: actions/setup-java@v4
with:
java-version: ${{ matrix.jdk }}
distribution: 'temurin'
Expand All @@ -43,3 +43,18 @@ jobs:

- name: Test with Gradle
run: ./gradlew check --stacktrace --no-daemon

gradle-scan:
name: Snyk gradle scan
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4

- name: Run Snyk to check build.gradle for vulnerabilities
uses: snyk/actions/gradle-jdk17@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
command: test
args: --severity-threshold=high --org=f310ee2f-5552-444d-84ee-ec8c44c33adb
14 changes: 14 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,3 +38,17 @@ jobs:
OSSRH_TOKEN: ${{ secrets.OSSRH_TOKEN }}
OSSRH_GPG_SECRET_KEY: ${{ secrets.OSSRH_GPG_SECRET_KEY }}
OSSRH_GPG_SECRET_KEY_PASSWORD: ${{ secrets.OSSRH_GPG_SECRET_KEY_PASSWORD }}

gradle-monitor:
name: Snyk gradle monitor
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Run Snyk to monitor build.gradle for vulnerabilities
uses: snyk/actions/gradle-jdk17@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
command: monitor
args: --org=f310ee2f-5552-444d-84ee-ec8c44c33adb --project-name=wiremock-jwt-extension --policy-path=.snyk

0 comments on commit 89fad75

Please sign in to comment.