Skip to content

Commit d58e20d

Browse files
committed
Refactor security workflow: remove unused environment variables and dependency scanning steps
Signed-off-by: Denis Arslanbekov <[email protected]>
1 parent 8975d48 commit d58e20d

File tree

1 file changed

+4
-11
lines changed

1 file changed

+4
-11
lines changed

.github/workflows/security.yml

Lines changed: 4 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -26,15 +26,8 @@ jobs:
2626
uses: securego/gosec@master
2727
with:
2828
args: ./...
29-
env:
30-
CLOUDCONNEXA_BASE_URL: ${{ vars.CLOUDCONNEXA_BASE_URL }}
31-
CLOUDCONNEXA_CLIENT_ID: ${{ secrets.CLOUDCONNEXA_CLIENT_ID }}
32-
CLOUDCONNEXA_CLIENT_SECRET: ${{ secrets.CLOUDCONNEXA_CLIENT_SECRET }}
3329

34-
- name: Generate dependencies list
35-
run: go list -json -m all > go.list
36-
37-
- name: Run nancy for dependency scanning
38-
uses: sonatype-nexus-community/nancy-github-action@main
39-
with:
40-
goListFile: go.list
30+
- name: Run govulncheck
31+
run: |
32+
go install golang.org/x/vuln/cmd/govulncheck@latest
33+
govulncheck ./...

0 commit comments

Comments
 (0)