From fc751fc2efb7d57ad16c521a7202a11a7122fda6 Mon Sep 17 00:00:00 2001 From: "nikita.smirnov" Date: Mon, 9 Dec 2024 12:39:33 +0400 Subject: [PATCH 1/2] Added dependencies scan workflow --- .github/workflows/scan.yml | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 .github/workflows/scan.yml diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml new file mode 100644 index 0000000..613d18d --- /dev/null +++ b/.github/workflows/scan.yml @@ -0,0 +1,12 @@ +name: Scan licenses and vulnerabilities in java project + +on: + workflow_dispatch: + schedule: + - cron: '0 0 * * 1' + +jobs: + build: + uses: th2-net/.github/.github/workflows/compound-java-scan.yml@main + secrets: + nvd-api-key: ${{ secrets.NVD_APIKEY }} \ No newline at end of file From 9cedaf56a5dad74664ec86cf30586f36427bd07d Mon Sep 17 00:00:00 2001 From: "nikita.smirnov" Date: Mon, 9 Dec 2024 12:40:07 +0400 Subject: [PATCH 2/2] Added dependencies scan workflow --- .github/workflows/ci-unwelcome-words.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/ci-unwelcome-words.yml b/.github/workflows/ci-unwelcome-words.yml index 4e5f3a6..12ffb5e 100644 --- a/.github/workflows/ci-unwelcome-words.yml +++ b/.github/workflows/ci-unwelcome-words.yml @@ -5,6 +5,7 @@ on: jobs: test: + if: github.actor != 'dependabot[bot]' runs-on: ubuntu-20.04 steps: - uses: actions/checkout@v4