From 6622770574f2518a9cd4a00d43099d7ad4a6744d Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Sat, 26 Oct 2024 17:25:32 -0300 Subject: [PATCH] feat: add OWASP dependency check Signed-off-by: Vitor Mattos --- .github/workflows/owasp-dependency-check.yml | 30 ++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 .github/workflows/owasp-dependency-check.yml diff --git a/.github/workflows/owasp-dependency-check.yml b/.github/workflows/owasp-dependency-check.yml new file mode 100644 index 000000000..e06cf40df --- /dev/null +++ b/.github/workflows/owasp-dependency-check.yml @@ -0,0 +1,30 @@ +# SPDX-FileCopyrightText: 2024 LibreCode coop and contributors +# SPDX-License-Identifier: AGPL-3.0-or-later + +name: "OWASP Dependency-Check" + +on: pull_request + +jobs: + dependency-check: + runs-on: ubuntu-latest + steps: + - name: Check out code + uses: actions/checkout@v2 + + - name: Run OWASP Dependency-Check + uses: dependency-check/Dependency-Check_Action@main + with: + format: 'ALL' + project: 'LibreSign' + path: './' + args: > + --failOnCVSS 7 + --enableRetired + --enableExperimental + + - name: Upload Dependency-Check report + uses: actions/upload-artifact@master + with: + name: dependency-check-report + path: dependency-check-report.html