Skip to content

21 nov 24 dependabot (#16625) #644

21 nov 24 dependabot (#16625)

21 nov 24 dependabot (#16625) #644

Workflow file for this run

name: Snyk Java/Kotlin scan
# refresh Snyk console results for Java/Kotlin scans when merging with main
on:
push:
branches:
- main
paths:
- "prime-router/**"
- "submissions/**"
- "shared/**"
- "auth/**"
jobs:
pre_job:
name: Pre Job
runs-on: ubuntu-latest
outputs:
has_router_change: ${{ steps.build_vars.outputs.has_router_change }}
steps:
- name: "Check out changes"
uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938
- name: Build vars
id: build_vars
uses: ./.github/actions/build-vars
snyk:
name: Snyk tests
runs-on: ubuntu-latest
needs: pre_job
strategy:
fail-fast: false
matrix:
folder: [prime-router, submissions, auth, shared]
steps:
- uses: actions/checkout@d632683dd7b4114ad314bca15554477dd762a938
- uses: snyk/actions/setup@b98d498629f1c368650224d6d212bf7dfa89e4bf
- name: Set up JDK 17 to generate backend coverage stats
uses: actions/setup-java@b36c23c0d998641eff861008f374ee103c25ac73
with:
java-version: "17"
distribution: "temurin"
cache: "gradle"
- uses: gradle/actions/setup-gradle@d156388eb19639ec20ade50009f3d199ce1e2808
- name: Snyk Monitor
working-directory: ${{ matrix.folder }}
run: snyk monitor --org=prime-reportstream
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}