Skip to content

Configure Renovate

Configure Renovate #58

Workflow file for this run

name: CI Scan
on:
pull_request:
branches:
- main
push:
branches:
- main
workflow_run:
workflows: ["CI Test"]
types:
- completed
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
jobs:
scan:
name: Scan
runs-on: ubuntu-20.04
steps:
- name: Check out Git repository
uses: actions/checkout@v3
- name: Run trivy for vulnerabilities
uses: aquasecurity/trivy-action@master
with:
scan-type: 'fs'
ignore-unfixed: true
format: 'github'
severity: 'HIGH,CRITICAL'
- name: Run Gosec Security Scanner
uses: securego/gosec@master
with:
args: ./...