-
Notifications
You must be signed in to change notification settings - Fork 0
/
action.yml
74 lines (70 loc) · 2.29 KB
/
action.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
name: 'Clojure NVD Scan'
description: 'Scans a Clojure deps.edn project for vulnerabilities'
inputs:
nvd-api-key:
description: 'NVD API key'
required: true
working-directory:
description: 'Directory in which to execute the NVD scan'
required: false
config-filename:
description: 'Config file path'
required: false
default: '""'
aliases:
description: 'colon separated list of deps.edn alias(es) to run the scan on'
required: false
default: ''
clojure-version:
description: 'clojure cli version'
required: false
default: '1.11.3.1463'
nvd-clojure-version:
description: 'version of the nvd-clojure tool'
required: false
default: 'RELEASE'
dependency-check-version:
description: 'version of org.owasp/dependency-check-core'
required: false
default: 'RELEASE'
java-opts:
description: 'options for the JVM'
required: false
default: '-Xmx1g'
runs:
using: "composite"
steps:
- uses: DeLaGuardo/[email protected]
with:
cli: ${{ inputs.clojure-version }}
- name: Cache maven
uses: actions/cache@v4
env:
cache-name: cache-maven
with:
path: ~/.m2
key: ${{ runner.os }}-nvd-${{ env.cache-name }}-${{ hashFiles('**/deps.edn') }}
restore-keys: |
${{ runner.os }}-nvd-${{ env.cache-name }}-
${{ runner.os }}-nvd-
${{ runner.os }}-
save-always: true
- name: Cache gitlibs
uses: actions/cache@v4
env:
cache-name: cache-gitlibs
with:
path: ~/.gitlibs
key: ${{ runner.os }}-nvd-${{ env.cache-name }}-${{ hashFiles('**/deps.edn') }}
restore-keys: |
${{ runner.os }}-nvd-${{ env.cache-name }}-
${{ runner.os }}-nvd-
${{ runner.os }}-
save-always: true
- name: NVD Scan
run: clojure -Sdeps '{:deps {nvd-clojure/nvd-clojure {:mvn/version "${{ inputs.nvd-clojure-version }}"} org.owasp/dependency-check-core {:mvn/version "${{ inputs.dependency-check-version }}"}}}' -M -m nvd.task.check ${{ inputs.config-filename }} "$(clojure -A:${{ inputs.aliases }} -Spath)"
working-directory: ${{ inputs.working-directory }}
shell: bash
env:
NVD_API_TOKEN: ${{ inputs.nvd-api-key }}
JAVA_OPTS: ${{ inputs.java-opts }}