You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@camel.apache.org by pc...@apache.org on 2023/07/31 07:05:18 UTC

[camel-k] branch main updated: feat(ci): Add govulncheck as ci workflow

This is an automated email from the ASF dual-hosted git repository.

pcongiusti pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-k.git


The following commit(s) were added to refs/heads/main by this push:
     new d452b04bf feat(ci): Add govulncheck as ci workflow
d452b04bf is described below

commit d452b04bf0f92823972f0c2aa6bb7f080ce8e2b8
Author: Gaelle Fournier <ga...@gmail.com>
AuthorDate: Fri Jul 28 16:36:08 2023 +0200

    feat(ci): Add govulncheck as ci workflow
---
 .github/workflows/security.yaml | 57 +++++++++++++++++++++++++++++++++++++++++
 1 file changed, 57 insertions(+)

diff --git a/.github/workflows/security.yaml b/.github/workflows/security.yaml
new file mode 100644
index 000000000..032ab7165
--- /dev/null
+++ b/.github/workflows/security.yaml
@@ -0,0 +1,57 @@
+# ---------------------------------------------------------------------------
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements.  See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License.  You may obtain a copy of the License at
+#
+#      http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+# ---------------------------------------------------------------------------
+
+name: security
+
+on:
+  pull_request:
+    branches:
+      - main
+      - "release-*"
+    paths:
+      - '**.go'
+      - '**.sum'
+      - '**.mod'
+  push:
+    branches:
+      - main
+      - "release-*"
+    paths:
+      - '**.go'
+      - '**.sum'
+      - '**.mod'
+
+concurrency:
+  group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
+  cancel-in-progress: true
+
+jobs:
+  security:
+    runs-on: ubuntu-latest
+    steps:
+      - name: Check out code
+        uses: actions/checkout@v3
+      - name: Install Go
+        uses: actions/setup-go@v4
+        with:
+          go-version: 1.20.x
+      - name: Install govulncheck
+        run: go install golang.org/x/vuln/cmd/govulncheck@latest
+        shell: bash
+      - name: Run govulncheck
+        run: govulncheck ./...
+        shell: bash
\ No newline at end of file