owasp-dependency-check.yaml 1.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950
  1. #
  2. # Licensed to the Apache Software Foundation (ASF) under one or more
  3. # contributor license agreements. See the NOTICE file distributed with
  4. # this work for additional information regarding copyright ownership.
  5. # The ASF licenses this file to You under the Apache License, Version 2.0
  6. # (the "License"); you may not use this file except in compliance with
  7. # the License. You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. #
  17. name: OWASP Dependency Check
  18. on:
  19. push:
  20. branches:
  21. - dev
  22. pull_request:
  23. paths:
  24. - '**/pom.xml'
  25. env:
  26. MAVEN_OPTS: -Dmaven.wagon.httpconnectionManager.ttlSeconds=25 -Dmaven.wagon.http.retryHandler.count=3
  27. jobs:
  28. build:
  29. runs-on: ubuntu-latest
  30. steps:
  31. - uses: actions/checkout@v2
  32. with:
  33. submodules: true
  34. - name: Set up JDK 8
  35. uses: actions/setup-java@v2
  36. with:
  37. java-version: 8
  38. distribution: 'adopt'
  39. - name: Run OWASP Dependency Check
  40. run: ./mvnw -B clean install verify dependency-check:check -DskipDepCheck=false -Dmaven.test.skip=true -Dspotless.skip=true
  41. - name: Upload report
  42. uses: actions/upload-artifact@v3
  43. if: ${{ cancelled() || failure() }}
  44. continue-on-error: true
  45. with:
  46. name: dependency report
  47. path: target/dependency-check-report.html