mirror of
https://github.com/argoproj/argo-cd
synced 2026-04-21 08:57:17 +00:00
Some checks are pending
Integration tests / changes (push) Waiting to run
Integration tests / Ensure Go modules synchronicity (push) Blocked by required conditions
Integration tests / Build & cache Go code (push) Blocked by required conditions
Integration tests / Lint Go code (push) Blocked by required conditions
Integration tests / Run unit tests for Go packages (push) Blocked by required conditions
Integration tests / Run unit tests with -race for Go packages (push) Blocked by required conditions
Integration tests / Check changes to generated code (push) Blocked by required conditions
Integration tests / Build, test & lint UI code (push) Blocked by required conditions
Integration tests / shellcheck (push) Waiting to run
Integration tests / Process & analyze test artifacts (push) Blocked by required conditions
Integration tests / Run end-to-end tests (push) Blocked by required conditions
Integration tests / E2E Tests - Composite result (push) Blocked by required conditions
Code scanning - action / CodeQL-Build (push) Waiting to run
Image / set-vars (push) Waiting to run
Image / build-only (push) Blocked by required conditions
Image / build-and-publish (push) Blocked by required conditions
Image / build-and-publish-provenance (push) Blocked by required conditions
Image / Deploy (push) Blocked by required conditions
Scorecards supply-chain security / Scorecards analysis (push) Waiting to run
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
46 lines
1.5 KiB
YAML
46 lines
1.5 KiB
YAML
name: Snyk report update
|
|
on:
|
|
workflow_dispatch: {}
|
|
schedule:
|
|
- cron: '0 0 * * 0' # midnight every Sunday
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
env:
|
|
# a workaround to disable harden runner
|
|
STEP_SECURITY_HARDEN_RUNNER: ${{ vars.disable_harden_runner }}
|
|
|
|
jobs:
|
|
snyk-report:
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
if: github.repository == 'argoproj/argo-cd'
|
|
name: Update Snyk report in the docs directory
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
if: ${{ vars.disable_harden_runner != 'true' }}
|
|
uses: step-security/harden-runner@8d3c67de8e2fe68ef647c8db1e6a09f647780f40 # v2.19.0
|
|
with:
|
|
egress-policy: audit
|
|
agent-enabled: "false"
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Build reports
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
|
|
run: |
|
|
make snyk-report
|
|
pr_branch="snyk-update-$(echo $RANDOM | md5sum | head -c 20)"
|
|
git checkout -b "$pr_branch"
|
|
git config --global user.email 'ci@argoproj.com'
|
|
git config --global user.name 'CI'
|
|
git add docs/snyk
|
|
git commit -m "[Bot] docs: Update Snyk reports" --signoff
|
|
git push --set-upstream origin "$pr_branch"
|
|
gh pr create -B master -H "$pr_branch" --title '[Bot] docs: Update Snyk report' --body ''
|