Skip to content

Security Scan

Security Scan #26

Workflow file for this run

name: Security Scan
on:
push:
branches: [ main, master ]
pull_request_target:
types: [ labeled ]
schedule:
- cron: '0 9 * * 1' # Weekly on Monday at 9 AM UTC
permissions:
contents: read
pull-requests: write
security-events: write
jobs:
jfrog-audit:
if: github.event_name == 'push' || contains(github.event.pull_request.labels.*.name, 'safe to test')
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}
- name: Setup JDK 17
uses: actions/setup-java@v4
with:
java-version: '17'
distribution: 'temurin'
cache: maven
- name: Set up JFrog CLI
uses: jfrog/setup-jfrog-cli@v4
env:
JF_URL: ${{ secrets.JF_URL }}
JF_ACCESS_TOKEN: ${{ secrets.JF_ACCESS_TOKEN }}
- name: Run JFrog Audit
run: jf audit
- name: Run Tests
run: mvn clean test -B
- name: Remove label
if: always() && github.event_name == 'pull_request_target'
uses: actions/github-script@v7
with:
script: |
github.rest.issues.removeLabel({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
name: 'safe to test'
})