-
Notifications
You must be signed in to change notification settings - Fork 567
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Signed-off-by: ҉αkα x⠠⠵ <[email protected]>
- Loading branch information
1 parent
b49cf28
commit 0cd0dd1
Showing
1 changed file
with
74 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,74 @@ | ||
# This workflow uses actions that are not certified by GitHub. | ||
# They are provided by a third-party and are governed by | ||
# separate terms of service, privacy policy, and support | ||
# documentation. | ||
# Frogbot Scan Pull Request does the following: | ||
# Automatically scans new pull requests for security vulnerabilities. | ||
# Uses JFrog Xray to scan the project. | ||
# Read more about Frogbot here - https://github.com/jfrog/frogbot#frogbot | ||
|
||
# Some projects require creating a frogbot-config.yml file. Read more about it here - https://github.com/jfrog/frogbot/blob/master/docs/frogbot-config.md | ||
|
||
name: "Frogbot Scan Pull Request" | ||
on: | ||
pull_request_target: | ||
types: [ opened, synchronize ] | ||
permissions: | ||
pull-requests: write | ||
contents: read | ||
jobs: | ||
scan-pull-request: | ||
runs-on: ubuntu-latest | ||
# A pull request needs to be approved, before Frogbot scans it. Any GitHub user who is associated with the | ||
# "frogbot" GitHub environment can approve the pull request to be scanned. | ||
# Read more here (Install Frogbot Using GitHub Actions): https://github.com/jfrog/frogbot/blob/master/docs/install-github.md | ||
environment: frogbot | ||
steps: | ||
- uses: actions/checkout@v2 | ||
with: | ||
ref: ${{ github.event.pull_request.head.sha }} | ||
|
||
# IMPORTANT: | ||
# 1. See the following link for information about the tools that need to be installed for Frogbot to work - https://github.com/jfrog/frogbot/tree/master/docs/templates/github-actions/scan-and-fix | ||
# 2. Some projects require creating a frogbot-config.yml file. Read more about it here - https://github.com/jfrog/frogbot/blob/master/docs/frogbot-config.md | ||
|
||
- uses: jfrog/frogbot@8fbeca612957ae5f5f0c03a19cb6e59e237026f3 # v2.10.0 | ||
env: | ||
# [Mandatory if the two conditions below are met] | ||
# 1. The project uses npm, yarn 2, NuGet or .NET to download its dependencies | ||
# 2. The `installCommand` variable isn't set in your frogbot-config.yml file. | ||
# | ||
# The command that installs the project dependencies (e.g "npm i", "nuget restore" or "dotnet restore") | ||
# JF_INSTALL_DEPS_CMD: "" | ||
|
||
# [Mandatory] | ||
# JFrog platform URL | ||
JF_URL: ${{ secrets.JF_URL }} | ||
|
||
# [Mandatory if JF_USER and JF_PASSWORD are not provided] | ||
# JFrog access token with 'read' permissions on Xray service | ||
JF_ACCESS_TOKEN: ${{ secrets.JF_ACCESS_TOKEN }} | ||
|
||
# [Mandatory if JF_ACCESS_TOKEN is not provided] | ||
# JFrog username with 'read' permissions for Xray. Must be provided with JF_PASSWORD | ||
# JF_USER: ${{ secrets.JF_USER }} | ||
|
||
# [Mandatory if JF_ACCESS_TOKEN is not provided] | ||
# JFrog password. Must be provided with JF_USER | ||
# JF_PASSWORD: ${{ secrets.JF_PASSWORD }} | ||
|
||
# [Mandatory] | ||
# The GitHub token automatically generated for the job | ||
JF_GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
|
||
# [Optional] | ||
# If the machine that runs Frogbot has no access to the internat, set the name of a remote repository | ||
# in Artifactory, which proxies https://releases.jfrog.io/artifactory | ||
# The 'frogbot' executable and other tools it needs will be downloaded through this repository. | ||
# JF_RELEASES_REPO: "" | ||
|
||
# [Optional] | ||
# Frogbot will download the project dependencies, if they're not cached locally. To download the | ||
# dependencies from a virtual repository in Artifactory, set the name of of the repository. There's no | ||
# need to set this value, if it is set in the frogbot-config.yml file. | ||
# JF_DEPS_REPO: "" |