- Updated the 'checkout' action to version 4 for consistency across workflows. - Added a 'Setup Go' step to initialize the Go environment using the latest action version. - Modified the OSV scan script to generalize vulnerability reporting, removing specific severity checks for a broader output.
26 lines
508 B
YAML
26 lines
508 B
YAML
name: OSV-Scanner PR Scan
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [master]
|
|
merge_group:
|
|
branches: [master]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
scan-pr:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
|
|
|
- name: Setup Go
|
|
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
|
|
with:
|
|
go-version-file: 'go.mod'
|
|
|
|
- name: OSV scan
|
|
run: bash scripts/osv_scan.sh
|