From a24ce2d3efb93297f6f18be6b8cc469d0dd75bd1 Mon Sep 17 00:00:00 2001 From: strangelookingnerd <49242855+strangelookingnerd@users.noreply.github.com> Date: Thu, 20 Jun 2024 14:52:33 +0200 Subject: [PATCH 1/2] Enable Jenkins Security Scan --- .github/workflows/jenkins-security-scan.yml | 22 +++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/workflows/jenkins-security-scan.yml diff --git a/.github/workflows/jenkins-security-scan.yml b/.github/workflows/jenkins-security-scan.yml new file mode 100644 index 00000000..7d116398 --- /dev/null +++ b/.github/workflows/jenkins-security-scan.yml @@ -0,0 +1,22 @@ +name: Jenkins Security Scan + +on: + push: + branches: + - main + - master + pull_request: + types: [ opened, synchronize, reopened ] + workflow_dispatch: + +permissions: + security-events: write + contents: read + actions: read + +jobs: + security-scan: + uses: jenkins-infra/jenkins-security-scan/.github/workflows/jenkins-security-scan.yaml@v2 + with: + java-cache: 'maven' # Optionally enable use of a build dependency cache. Specify 'maven' or 'gradle' as appropriate. + java-version: 17 # What version of Java to set up for the build. From 730904b92236082fafb27a28aca5e3b33b7038b2 Mon Sep 17 00:00:00 2001 From: strangelookingnerd <49242855+strangelookingnerd@users.noreply.github.com> Date: Fri, 28 Jun 2024 12:40:51 +0200 Subject: [PATCH 2/2] Enable Jenkins Security Scan --- .github/workflows/jenkins-security-scan.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/workflows/jenkins-security-scan.yml b/.github/workflows/jenkins-security-scan.yml index 7d116398..c7b41fc2 100644 --- a/.github/workflows/jenkins-security-scan.yml +++ b/.github/workflows/jenkins-security-scan.yml @@ -3,7 +3,6 @@ name: Jenkins Security Scan on: push: branches: - - main - master pull_request: types: [ opened, synchronize, reopened ] @@ -19,4 +18,4 @@ jobs: uses: jenkins-infra/jenkins-security-scan/.github/workflows/jenkins-security-scan.yaml@v2 with: java-cache: 'maven' # Optionally enable use of a build dependency cache. Specify 'maven' or 'gradle' as appropriate. - java-version: 17 # What version of Java to set up for the build. + # java-version: 21 # Optionally specify what version of Java to set up for the build, or remove to use a recent default.