Skip to content

Commit

Permalink
TB-52 Legg til action for dependency review av Pull Requests
Browse files Browse the repository at this point in the history
* Submitter alle dependencies via Submission APIet
* Dette skal også gjøre at vi får innsikt i dependency graph og varsling om eventuelle sårbarheter
* Kjører dependency review pluginen som skal hente depedencies via submission APIet

* Tillater følgende lisenser: MIT og Apache 2.0
* Sjekker også etter sårbarheter i tillegg til lisenser i 3. parts libs
  • Loading branch information
henriwi committed Aug 28, 2024
1 parent 4cf8646 commit 14b91b1
Show file tree
Hide file tree
Showing 5 changed files with 57 additions and 10 deletions.
12 changes: 12 additions & 0 deletions .github/actions/setup-java/action.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
name: Setup java
description: Setup Java with correct version

runs:
using: composite

steps:
- name: Setup Java
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: '21'
5 changes: 1 addition & 4 deletions .github/workflows/build-deploy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,7 @@ jobs:
- name: Checkout project sources
uses: actions/checkout@v4
- name: Setup Java
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: '21'
uses: ./.github/actions/setup-java
- name: Run build and integration tests
run: ./gradlew build integrationTest
- name: Build and push docker
Expand Down
8 changes: 2 additions & 6 deletions .github/workflows/codeql.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,8 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Set up JDK 21
uses: actions/setup-java@v4
with:
java-version: '21'
distribution: 'temurin'
- name: Setup Java
uses: ./.github/actions/setup-java

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
Expand Down
24 changes: 24 additions & 0 deletions .github/workflows/dependency-review-pr.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
name: Dependency Review for PR
on:
pull_request:
branches: [ main ]

permissions:
contents: write
pull-requests: write

jobs:
dependency-review:
runs-on: ubuntu-latest
steps:
- name: Checkout project sources
uses: actions/checkout@v4
- name: Setup Java
uses: ./.github/actions/setup-java
- name: Dependency submission
uses: gradle/actions/dependency-submission@v4
- name: Dependency review
uses: actions/dependency-review-action@v4
with:
comment-summary-in-pr: true
allow-licenses: MIT, Apache-2.0
18 changes: 18 additions & 0 deletions .github/workflows/dependency-submission.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
name: Dependency Submission
on:
push:
branches: [ main ]

permissions:
contents: write

jobs:
dependency-submission:
runs-on: ubuntu-latest
steps:
- name: Checkout project sources
uses: actions/checkout@v4
- name: Setup Java
uses: ./.github/actions/setup-java
- name: Generate and submit dependency graph
uses: gradle/actions/dependency-submission@v4

0 comments on commit 14b91b1

Please sign in to comment.