Skip to content

Commit fafaf20

Browse files
committed
ci: vulnerability scan tweaks
Addendum for #125
1 parent 707d19b commit fafaf20

File tree

2 files changed

+7
-4
lines changed

2 files changed

+7
-4
lines changed

.github/workflows/nvd_scanner.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,10 +29,13 @@ jobs:
2929
cli: 'latest'
3030
bb: 'latest'
3131

32-
- name: Generate Cache Key
32+
- name: Generate Cache Key File
33+
# go with bash instead of bb, we have not downloaded our deps yet
3334
run: |
34-
bb --version
35-
bb latest-release nvd-clojure | tee nvd_check_helper_project/nvd-clojure-version.txt
35+
curl --fail -s \
36+
https://clojars.org/api/artifacts/nvd-clojure | \
37+
jq ".latest_release" | \
38+
tee nvd_check_helper_project/nvd-clojure-version.txt
3639
3740
- name: Restore NVD DB & Clojure Deps Cache
3841
# nvd caches its db under ~/.m2/repository/org/owasp so that it can

nvd_check_helper_project/deps.edn

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,4 @@
44
#_:clj-kondo/ignore
55
{:mvn/version "RELEASE"}
66
;; temporarily try bumping transitive dep to current release
7-
org.owasp/dependency-check-maven {:mvn/version "10.0.0"}}}
7+
org.owasp/dependency-check-core {:mvn/version "10.0.0"}}}

0 commit comments

Comments
 (0)