Skip to content

Commit 872ed35

Browse files
committed
ci(snyk): #277 add snyk code sast
1 parent bc056ab commit 872ed35

File tree

1 file changed

+14
-4
lines changed

1 file changed

+14
-4
lines changed

.github/workflows/pipeline.yml

+14-4
Original file line numberDiff line numberDiff line change
@@ -97,17 +97,27 @@ jobs:
9797
name: "Executing dependency vulnerability checks"
9898
env:
9999
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
100-
sast-code-snyk:
100+
sast-snyk:
101101
runs-on: ubuntu-latest
102102
needs: build
103103
steps:
104104
- uses: actions/checkout@v4
105-
- name: Run Snyk to static code analysis for vulnerabilities
106-
uses: snyk/actions/maven-3-jdk-21@master
105+
- uses: snyk/actions/maven-3-jdk-21@master
106+
name: Run Snyk scan for dependency and license
107107
env:
108108
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
109109
with:
110110
args: --severity-threshold=high
111+
- uses: actions/setup-java@v4
112+
with:
113+
distribution: adopt
114+
java-version: 21
115+
check-latest: true
116+
- uses: snyk/actions/setup@master
117+
- name: Snyk SAST code
118+
run: snyk code test
119+
env:
120+
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
111121
sast-iac-trivy-hadolint:
112122
runs-on: ubuntu-latest
113123
needs: build
@@ -131,7 +141,7 @@ jobs:
131141
- unit-test
132142
- mutation-test
133143
- dependency-vulnerability-analysis
134-
- sast-code-snyk
144+
- sast-snyk
135145
- sast-iac-trivy-hadolint
136146
steps:
137147
- uses: actions/checkout@v4

0 commit comments

Comments
 (0)