-
-
Notifications
You must be signed in to change notification settings - Fork 18
67 lines (62 loc) · 1.74 KB
/
Copy pathsecurity-scan.yml
File metadata and controls
67 lines (62 loc) · 1.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
# ------------------------------------------------------------------------------
# <auto-generated>
#
# This code was generated.
#
# - To turn off auto-generation set:
#
# [GitHubActions (AutoGenerate = false)]
#
# - To trigger manual generation invoke:
#
# fallout --generate-configuration GitHubActions_security-scan --host GitHubActions
#
# </auto-generated>
# ------------------------------------------------------------------------------
name: security-scan
on:
push:
branches:
- develop
- main
- 'release/*'
- 'support/*'
paths-ignore:
- 'docs/**'
- '.assets/**'
- '**/*.md'
permissions:
security-events: write
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
ubuntu-latest:
name: ubuntu-latest
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: 'Cache: .fallout/temp, ~/.nuget/packages'
uses: actions/cache@v6
with:
path: |
.fallout/temp
~/.nuget/packages
key: ${{ runner.os }}-${{ hashFiles('**/global.json', '**/*.csproj', '**/Directory.Packages.props') }}
- name: 'Setup: .NET SDK'
uses: actions/setup-dotnet@v6
with:
global-json-file: global.json
- name: 'Restore: dotnet tools'
run: dotnet tool restore
- name: 'Run: PackageGuard'
run: dotnet fallout PackageGuard
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: 'Upload risk-report SARIF to GitHub code scanning'
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: output/packageguard/risk-report.sarif