diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index e4e59906..d926af04 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -45,30 +45,15 @@ jobs: if ($LastExitCode -ne 0) { throw "dotnet restore failed with exit code $LastExitCode" } - - name: 🔬 snyk opensource scan + - name: 🔬 snyk scan uses: snyk/actions/dotnet@master continue-on-error: true env: SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} with: - args: --sarif-file-output=snyk/opensource.sarif --all-projects --exclude=Objectivity.AutoFixture.XUnit2.AutoFakeItEasy.Tests,Objectivity.AutoFixture.XUnit2.AutoMoq.Tests,Objectivity.AutoFixture.XUnit2.AutoNSubstitute.Tests,Objectivity.AutoFixture.XUnit2.Core.Tests - - name: 🔬 snyk code scan - uses: snyk/actions/dotnet@master - continue-on-error: true - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - with: - args: --sarif-file-output=snyk/code.sarif - command: code test - - name: 📈 snyk monitor - uses: snyk/actions/dotnet@master - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - with: - args: --all-projects --exclude=Objectivity.AutoFixture.XUnit2.AutoFakeItEasy.Tests,Objectivity.AutoFixture.XUnit2.AutoMoq.Tests,Objectivity.AutoFixture.XUnit2.AutoNSubstitute.Tests,Objectivity.AutoFixture.XUnit2.Core.Tests - command: monitor + args: --sarif-file-output=snyk.sarif --all-projects --exclude=Objectivity.AutoFixture.XUnit2.AutoFakeItEasy.Tests,Objectivity.AutoFixture.XUnit2.AutoMoq.Tests,Objectivity.AutoFixture.XUnit2.AutoNSubstitute.Tests,Objectivity.AutoFixture.XUnit2.Core.Tests - name: 📊 upload sarif file for GitHub Advanced Security Dashboard uses: github/codeql-action/upload-sarif@v4 with: - sarif_file: snyk + sarif_file: snyk.sarif if: ${{ always() }}