Skip to content

chore: bump actions/create-github-app-token from 2.1.4 to 2.2.0 #514

chore: bump actions/create-github-app-token from 2.1.4 to 2.2.0

chore: bump actions/create-github-app-token from 2.1.4 to 2.2.0 #514

Workflow file for this run

name: Security
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
schedule:
- cron: "0 0 * * 1" # every Monday at 00:00 UTC
jobs:
osv-scanner:
if: "!startsWith(github.event.head_commit.message, 'bump:')"
runs-on: ubuntu-latest
container:
image: ghcr.io/google/osv-scanner:v2.1.0@sha256:9a1ba57d2a1506c9e9d0dfbeaf46346507e829745b70d47d77e12c38e66de8d7
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: Run OSV Scanner
run: |
/osv-scanner --format table -r .
semgrep:
if: github.event_name != 'schedule' && !startsWith(github.event.head_commit.message, 'bump:')
runs-on: ubuntu-latest
container:
image: returntocorp/semgrep:1.128.1@sha256:144d315f7354c2b2c53021a76165a500f67252c47464be75e951b67050f54a9e
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: Run Semgrep
run: |
semgrep scan --config auto
twyn:
if: github.event_name != 'schedule' && !startsWith(github.event.head_commit.message, 'bump:')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: Run twyn
uses: elementsinteractive/twyn-action@v1
id: app-token
with:
publish: true
github-token: ${{ secrets.GITHUB_TOKEN }}
version: v6