Skip to content

ci(deps): bump the codeql group with 3 updates #505

ci(deps): bump the codeql group with 3 updates

ci(deps): bump the codeql group with 3 updates #505

Workflow file for this run

---
#################################
#################################
## Super Linter GitHub Actions ##
#################################
#################################
name: Lint Code Base
#
# Documentation:
# https://help.github.com/en/articles/workflow-syntax-for-github-actions
#
#############################
# Start the job on all push #
#############################
on:
push:
pull_request:
schedule:
- cron: "0 0 * * 0"
workflow_dispatch:
permissions: {}
###############
# Set the Job #
###############
jobs:
super-linter:
# Name the Job
name: Lint Code Base
# Set the agent to run on
runs-on: ubuntu-latest
############################################
# Grant status permission for MULTI_STATUS #
############################################
permissions:
# Required to read the code
contents: read
# Required to access the container image
packages: read
# Required to write the status
statuses: write
##################
# Load all steps #
##################
steps:
##########################
# Checkout the code base #
##########################
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Full git history is needed to get a proper list of changed
# files within `super-linter`
fetch-depth: 0
persist-credentials: false
#############################################################
# Give Trivy a local Maven repository to resolve POMs from #
# (see TRIVY_OFFLINE_SCAN below). Only the runs that enable #
# Trivy's vulnerability scanner need it. #
#############################################################
- name: Restore Maven dependencies
if: ${{ github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' }}
# Same path and key as the Maven workflow, so this reuses the cache
# that workflow saves. Restore only: this workflow never saves a
# cache of its own.
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .m2/repository
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
restore-keys: |
${{ runner.os }}-maven-
- name: Move Maven dependencies where Trivy looks for them
if: ${{ github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' }}
shell: bash
run: |
set -euo pipefail
IFS=$'\n\t'
if [ ! -d .m2/repository ]; then
echo "No Maven cache restored: Trivy will report dependencies without their versions"
exit 0
fi
# super-linter is a Docker action, and the runner mounts
# "${RUNNER_TEMP}/_github_home" as the home directory inside the
# container, which is where Trivy looks for .m2/repository. Moving
# the dependencies out of the workspace also keeps Trivy from
# scanning the cached jars themselves.
mkdir -p "${RUNNER_TEMP}/_github_home/.m2"
mv .m2/repository "${RUNNER_TEMP}/_github_home/.m2/repository"
################################
# Run Linter against code base #
################################
- name: Lint Code Base
uses: super-linter/super-linter@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0
env:
BIOME_CONFIG_PATH: .biome.json
DEFAULT_BRANCH: main
ENABLE_GITHUB_ACTIONS_STEP_SUMMARY: true
ENFORCE_COMMITLINT_CONFIGURATION_CHECK: true
FILTER_REGEX_EXCLUDE: "(gradlew|gradlew\\.bat|gradle/.*|mvnw|mvnw\\.cmd|\\.m2/.*|\\.mvn/.*)$"
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_ACTIONS_ZIZMOR_CONFIG_FILE: .zizmor.yml
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
JAVA_FILE_NAME: google_checks.xml
LINTER_RULES_PATH: .
SAVE_SUPER_LINTER_SUMMARY: true
# Trivy's pom.xml analyzer resolves parent and BOM POMs from Maven
# Central even when the vuln scanner is off (Trivy 0.71.1, shipped
# with super-linter v8.7.0), and Maven Central answers "429 Too Many
# Requests" to Trivy's user agent from any IP, which aborts the whole
# run. Keep this unconditional rather than tying it to TRIVY_SCANNERS
# below: the runs that enable the vuln scanner get the same 429, so
# online resolution never succeeds there either. Trivy still resolves
# parent and BOM POMs from the local repository restored above, and a
# cache miss only costs coverage (a warning) instead of failing the
# run.
TRIVY_OFFLINE_SCAN: true
TRIVY_SCANNERS: ${{ (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && 'vuln,misconfig,secret' || 'misconfig,secret'}}
VALIDATE_ALL_CODEBASE: true
# Only lint commit messages when the run was triggered by a commit
# (push / pull_request); schedule and workflow_dispatch runs have no
# triggering commit for commitlint to check.
VALIDATE_GIT_COMMITLINT: ${{ (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && 'false' || '' }}