Skip to content

Commit

Permalink
Merge pull request #29 from google/update-to-v1.8.1
Browse files Browse the repository at this point in the history
Update to v1.8.1
  • Loading branch information
another-rex committed Jun 28, 2024
2 parents f0e45d2 + 3ea235a commit 3c399db
Show file tree
Hide file tree
Showing 6 changed files with 10 additions and 10 deletions.
6 changes: 3 additions & 3 deletions .github/workflows/osv-scanner-reusable-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ jobs:
- name: "Checkout target branch"
run: git checkout $GITHUB_BASE_REF
- name: "Run scanner on existing code"
uses: google/osv-scanner-action/osv-scanner-action@ba0b4d196d231340e0ae94ae00933c8be0984192 # v1.7.4
uses: google/osv-scanner-action/osv-scanner-action@cd72c04b43d9a3dbc85e56c1205e4d9b0e6a379b # v1.8.1
continue-on-error: true
with:
scan-args: |-
Expand All @@ -66,15 +66,15 @@ jobs:
- name: "Checkout current branch"
run: git checkout $GITHUB_SHA
- name: "Run scanner on new code"
uses: google/osv-scanner-action/osv-scanner-action@ba0b4d196d231340e0ae94ae00933c8be0984192 # v1.7.4
uses: google/osv-scanner-action/osv-scanner-action@cd72c04b43d9a3dbc85e56c1205e4d9b0e6a379b # v1.8.1
with:
scan-args: |-
--format=json
--output=new-results.json
${{ inputs.scan-args }}
continue-on-error: true
- name: "Run osv-scanner-reporter"
uses: google/osv-scanner-action/osv-reporter-action@ba0b4d196d231340e0ae94ae00933c8be0984192 # v1.7.4
uses: google/osv-scanner-action/osv-reporter-action@cd72c04b43d9a3dbc85e56c1205e4d9b0e6a379b # v1.8.1
with:
scan-args: |-
--output=${{ inputs.results-file-name }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/osv-scanner-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -64,15 +64,15 @@ jobs:
name: "${{ inputs.download-artifact }}"
path: "./"
- name: "Run scanner"
uses: google/osv-scanner-action/osv-scanner-action@ba0b4d196d231340e0ae94ae00933c8be0984192 # v1.7.4
uses: google/osv-scanner-action/osv-scanner-action@cd72c04b43d9a3dbc85e56c1205e4d9b0e6a379b # v1.8.1
with:
scan-args: |-
--output=results.json
--format=json
${{ inputs.scan-args }}
continue-on-error: true
- name: "Run osv-scanner-reporter"
uses: google/osv-scanner-action/osv-reporter-action@ba0b4d196d231340e0ae94ae00933c8be0984192 # v1.7.4
uses: google/osv-scanner-action/osv-reporter-action@cd72c04b43d9a3dbc85e56c1205e4d9b0e6a379b # v1.8.1
with:
scan-args: |-
--output=${{ inputs.results-file-name }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/osv-scanner-unified-workflow.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ permissions:
jobs:
scan-scheduled:
if: ${{ github.event_name == 'push' || github.event_name == 'schedule' }}
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@ba0b4d196d231340e0ae94ae00933c8be0984192" # v1.7.4
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@6d2b388dfd698241547c91007c380a52e5155ff7" # v1.8.1
with:
# Example of specifying custom arguments
scan-args: |-
Expand All @@ -44,7 +44,7 @@ jobs:
./
scan-pr:
if: ${{ github.event_name == 'pull_request' || github.event_name == 'merge_group' }}
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@ba0b4d196d231340e0ae94ae00933c8be0984192" # v1.7.4
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@6d2b388dfd698241547c91007c380a52e5155ff7" # v1.8.1
with:
# Example of specifying custom arguments
scan-args: |-
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# OSV-Scanner CI/CD Action

[![Release v1.7.4](https://img.shields.io/badge/release-v1.7.4-blue?style=flat)](https://github.com/google/osv-scanner-action/releases)
[![Release v1.8.1](https://img.shields.io/badge/release-v1.8.1-blue?style=flat)](https://github.com/google/osv-scanner-action/releases)
<!-- Hard coded release version -->

The OSV-Scanner CI/CD action leverages the [OSV.dev](https://osv.dev/) database and the [OSV-Scanner](https://google.github.io/osv-scanner/) CLI tool to track and notify you of known vulnerabilities in your dependencies for over 11 [languages and ecosystems](https://google.github.io/osv-scanner/supported-languages-and-lockfiles/).
Expand Down
2 changes: 1 addition & 1 deletion osv-reporter-action/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ inputs:
required: true
runs:
using: "docker"
image: "docker://ghcr.io/google/osv-scanner-action:v1.7.4"
image: "docker://ghcr.io/google/osv-scanner-action:v1.8.1"
entrypoint: /root/osv-reporter
args:
- "${{ inputs.scan-args }}"
2 changes: 1 addition & 1 deletion osv-scanner-action/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@ inputs:
./
runs:
using: "docker"
image: "docker://ghcr.io/google/osv-scanner-action:v1.7.4"
image: "docker://ghcr.io/google/osv-scanner-action:v1.8.1"
args:
- ${{ inputs.scan-args }}

0 comments on commit 3c399db

Please sign in to comment.