Skip to content

feature - read dev users from file #603

feature - read dev users from file

feature - read dev users from file #603

Workflow file for this run

---
name: code-and-dependencies-analysis
on:
pull_request:
types:
- opened
- synchronize
- reopened
- ready_for_review
jobs:
verify:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: s4u/[email protected]
with:
java-version: 17
java-distribution: temurin
maven-version: 3.8.6
- run: mvn verify --batch-mode
- name: Save test results
uses: scacap/action-surefire-report@v1
if: ${{ github.actor != 'dependabot[bot]' }}
- name: Publish OpenAPI definitions
uses: actions/upload-artifact@v4
with:
name: openapi
path: target/generated/openapi.json
- name: Publish code coverage to pull request
if: ${{ github.actor != 'dependabot[bot]' }}
uses: madrapps/[email protected]
with:
paths: ${{ github.workspace }}/target/jacoco-report/jacoco.xml
token: ${{ secrets.GITHUB_TOKEN }}
min-coverage-overall: 1
min-coverage-changed-files: 0
- name: Get branch name
if: ${{ github.actor != 'dependabot[bot]' }}
id: branch-name
uses: tj-actions/branch-names@v6
- name: Analyze build code
if: ${{ github.actor != 'dependabot[bot]' }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information, if any
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
run: mvn org.sonarsource.scanner.maven:sonar-maven-plugin:sonar -Dsonar.branch.target=${{ steps.branch-name.outputs.base_ref_branch}} -Dsonar.branch.name=${{ steps.branch-name.outputs.head_ref_branch }}
security-scan:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run Snyk to check for vulnerabilities
uses: snyk/actions/maven@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
continue-on-error: true
with:
command: test --severity-threshold=high --sarif-file-output=target/snyk-report/snyk.sarif
- name: Upload result to GitHub Code Scanning
uses: github/codeql-action/upload-sarif@v3
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
sarif_file: target/snyk-report/snyk.sarif
category: Snyk