diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index d3f40317a8..65e2b0d5e9 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -20,7 +20,7 @@ jobs: uses: step-security/harden-runner@8ca2b8b2ece13480cda6dacd3511b49857a23c09 # v2.5.1 with: disable-sudo: true - egress-policy: block + egress-policy: audit allowed-endpoints: > api.adoptium.net:443 api.foojay.io @@ -39,7 +39,7 @@ jobs: services.gradle.org:443 - uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0 - name: Run Snyk test - uses: snyk/actions/gradle@master + uses: snyk/actions/gradle-jdk11@master continue-on-error: true env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} @@ -57,9 +57,10 @@ jobs: with: sarif_file: snyk.sarif - name: Run Snyk monitor - uses: snyk/actions/gradle@master + uses: snyk/actions/gradle-jdk11@master continue-on-error: true env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} with: command: monitor + args: -- --no-configuration-cache