fix(ci): Snyk environment fix
This commit is contained in:
parent
54c1fbfd4b
commit
44b35f7066
@ -64,9 +64,11 @@ jobs:
|
|||||||
# SONAR_HOST_URL: ${{ secrets.SONARQUBE_HOST_URL }}
|
# SONAR_HOST_URL: ${{ secrets.SONARQUBE_HOST_URL }}
|
||||||
# SONAR_TOKEN: ${{ secrets.SONARQUBE_TOKEN }}
|
# SONAR_TOKEN: ${{ secrets.SONARQUBE_TOKEN }}
|
||||||
|
|
||||||
- name: Create requirements.txt for Snyk
|
- name: Set up environment for Snyk
|
||||||
run: |
|
run: |
|
||||||
uv pip freeze > requirements.txt
|
uv pip freeze > requirements.txt
|
||||||
|
mv pyproject.toml pyproject.toml.bak
|
||||||
|
mv uv.lock uv.lock.bak
|
||||||
|
|
||||||
- name: Snyk SAST Scan
|
- name: Snyk SAST Scan
|
||||||
uses: snyk/actions/python@master
|
uses: snyk/actions/python@master
|
||||||
@ -84,6 +86,12 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
command: test
|
command: test
|
||||||
args: --all-projects --exclude=.archive
|
args: --all-projects --exclude=.archive
|
||||||
|
|
||||||
|
- name: Reverse set up environment for Snyk
|
||||||
|
run: |
|
||||||
|
rm -f requirements.txt
|
||||||
|
mv pyproject.toml.bak pyproject.toml
|
||||||
|
mv uv.lock.bak uv.lock
|
||||||
|
|
||||||
# - name: Trivy Setup
|
# - name: Trivy Setup
|
||||||
# uses: aquasecurity/setup-trivy@v0.2.0
|
# uses: aquasecurity/setup-trivy@v0.2.0
|
||||||
@ -113,4 +121,3 @@ jobs:
|
|||||||
# ignore-unfixed: true
|
# ignore-unfixed: true
|
||||||
# vuln-type: 'os,library'
|
# vuln-type: 'os,library'
|
||||||
# severity: "CRITICAL,HIGH,MEDIUM"
|
# severity: "CRITICAL,HIGH,MEDIUM"
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user