yahavi
de925c96d9
Frogbot: Update to 2.21.0
2024-06-01 18:58:42 +03:00
Ross Rogers
7ea2dd7e08
Update Mayhem for API to reference new site
2024-05-21 14:38:32 -07:00
Marco Gario and GitHub
899b09ba54
Merge branch 'main' into patch-5
2024-05-13 11:29:02 +02:00
6702f0d2e3
Fortify Starter Workflow to use new Fortify AST Action ( #2245 )
...
* Update Fortify logo
* Update fortify workflow
Update positioning, Github action versions, Java version and add in Debricked packaging support
* Update fortify.properties.json
Update languages and creator
* Update fortify.yml
Update triggers based on latest starter workflow guidelines
* Update code-scanning/fortify.yml
Co-authored-by: James M. Greene <[email protected] >
* Update code-scanning/fortify.yml
Co-authored-by: James M. Greene <[email protected] >
* Update code-scanning/properties/fortify.properties.json
Co-authored-by: James M. Greene <[email protected] >
* Update code-scanning/fortify.yml
Co-authored-by: James M. Greene <[email protected] >
* Update code-scanning/fortify.yml
Co-authored-by: James M. Greene <[email protected] >
* Update code-scanning/fortify.yml
Co-authored-by: James M. Greene <[email protected] >
* Update fortify.yml
* Update fortify.properties.json
* Update fortify.yml
Update starter workflow to use new unified Fortify AST Action
* Update fortify.yml
* Update fortify.yml
* Update fortify.yml
Refine workflow comments
* Update fortify.yml
Bump checkout action version
* Update fortify.yml
* Update fortify.yml
* Update fortify.yml
One final clean up
* Update fortify.properties.json
* Update fortify.yml
* Update fortify.yml
* Update fortify.properties.json
Update with support for Bicep and Solidity
* Update fortify.properties.json
Uppercase "Solidity" for consistency
* Change v1 to commit hash
---------
Co-authored-by: James M. Greene <[email protected] >
Co-authored-by: Ruud Senden <[email protected] >
2024-05-06 13:57:14 +00:00
Chad Bentz and GitHub
b30fbdf5f2
Specify bash shell so that it doesn't fail if switching to 'windows`
2024-05-02 10:59:15 -04:00
Josh Soref
1830845916
Setup-Node: Update all workflows to use Setup-Node V4
...
* Switch default node version to 20
* Update version set to 18.x, 20.x, 22.x
Signed-off-by: Josh Soref <[email protected] >
2024-04-25 17:42:55 -04:00
Josh Soref
d51dfabea2
Artifacts: Update all workflows to use Artifacts V4
...
Signed-off-by: Josh Soref <[email protected] >
2024-04-25 16:11:16 -04:00
Josh Soref
545832af8b
Setup-Dotnet: Update all workflows to Setup-Dotnet V4
2024-04-25 14:27:37 -04:00
Josh Soref
37d6de723e
Setup-Java: Update all workflows to use Setup-Java V4
...
Signed-off-by: Josh Soref <[email protected] >
2024-04-25 14:15:25 -04:00
Dan Rigby and GitHub
8ff5c7e7bb
Merge branch 'main' into bump-actions
2024-04-25 12:51:52 -04:00
mponaws and GitHub
ac9c407320
Add starter-workflows for Policy Validator ( #2375 )
...
* Add starter-workflows for Policy Validator
* Add starter-workflows for Policy Validator
* Add starter-workflows for Policy Validator, removed references to GitHub secrets & S3 to keep it simple
2024-04-18 14:39:17 -05:00
Marco Gario and Anders Starcke Henriksen
a3194f5b47
Update CodeQL workflow to use packages:read permission.
...
Co-authored-by: Anders Starcke Henriksen <[email protected] >
2024-04-11 09:42:21 +02:00
ca5bcdc693
Add OSV-Scanner code scanning workflow ( #2350 )
...
* Add OSV-Scanner code scanning workflow
* Update code-scanning/osv-scanner.yml
Co-authored-by: Alexis Abril <[email protected] >
---------
Co-authored-by: Alexis Abril <[email protected] >
2024-04-09 22:21:33 -05:00
Josh Soref
cd4b67d0b4
Checkout: Update all workflows to use Checkout V4
2024-04-05 15:29:37 -04:00
Issy Long and GitHub
31a3e00dab
codeql: Clarify that hosted larger runners only exist on GHEC
...
- Part of https://github.com/github/code-scanning/issues/13748 .
2024-04-03 10:23:11 +01:00
efd31e5f0f
update soos dash action commit hash / sarif action version / logo ( #2317 )
...
* Update soos-dast-scan.yml
* Update soos-dast-scan.yml
* Update soos.svg
* Update code-scanning/soos-dast-scan.yml
Co-authored-by: Alexis Abril <[email protected] >
---------
Co-authored-by: Alexis Abril <[email protected] >
2024-04-01 15:11:05 -05:00
4620c76b38
update Scorecard Action hashes and version comments ( #2348 )
...
* update action hashes and version comments
ossf/scorecard-action v2.1.2 is old and doesnt work after a Sigstore
change. https://blog.sigstore.dev/tuf-root-update/
Signed-off-by: Spencer Schrock <[email protected] >
* downgrade actions/upload-artifact to node20 version of v3
dependabot will suggest upgrade to v4.3.1 for repos that can upgrade.
note: v3.pre.node20 is how dependabot refers to the pinned hash, so
use that so it can upgrade the comment
Signed-off-by: Spencer Schrock <[email protected] >
* upgrade github/codeql-action/upload-sarif to v3.24.9
Signed-off-by: Spencer Schrock <[email protected] >
---------
Signed-off-by: Spencer Schrock <[email protected] >
Co-authored-by: Alexis Abril <[email protected] >
2024-03-27 13:25:03 -07:00
Andreas Deininger and GitHub
831e9cb8e4
Bump workflow actions of various starter files ( #2210 )
2024-03-27 10:51:41 -07:00
Marco Gario
fdbad9c74f
Update codeql.yml
...
links to docs
2024-03-26 13:45:32 +01:00
Marco Gario and GitHub
97c6254b5e
Merge branch 'main' into update_codeql_template
2024-03-26 13:35:12 +01:00
Marco Gario and GitHub
aad9272438
Update codeql.yml
...
Limit matrix information in the job name to language by default
2024-03-26 13:18:17 +01:00
Chad Bentz and GitHub
03277899f0
tfsec latest v0.1.4 ( #2318 )
2024-03-06 15:46:46 -06:00
4a8c4e08b0
Update code-scanning/codeql.yml
...
Co-authored-by: Henry Mercer <[email protected] >
2024-02-19 15:57:02 +01:00
8a973982d1
Update code-scanning/codeql.yml
...
Co-authored-by: Henry Mercer <[email protected] >
2024-02-19 15:54:06 +01:00
Marco Gario and GitHub
05e4581159
Update codeql.yml with new build-mode
2024-02-15 09:01:39 +01:00
8aab15dd49
Update code-scanning/dependency-review.yml
...
begone, whitespace
Co-authored-by: Chad Bentz <[email protected] >
2024-02-07 09:06:01 -06:00
Jon Janego and GitHub
ba9d3788e4
Changing default behavior to include comment summary in PR
...
also gave the workflow the appropriate permissions required, pull-requests: write
2024-02-06 12:55:25 -06:00
SOOS-GSteen and GitHub
6e4aae97ef
soos-dast-scan.yml update ( #2240 )
...
* Update soos-dast-scan.yml
* use major version syntax
* code review
* lint
* Update soos-dast-scan.yml
2024-02-06 10:44:04 -06:00
Jon Janego and GitHub
cea0111003
Update dependency-review.yml
...
removing extra whitespace
2024-01-29 14:38:17 -06:00
Chris Campbell and GitHub
e67682c31c
Add perms for comment-summary-in-pr
2024-01-29 10:09:37 +00:00
Chris Campbell and GitHub
a6ab3d3f95
Update dependency-review.yml
2024-01-29 09:05:18 +00:00
Chris Campbell and GitHub
f9970771a8
Update dependency-review-action to v4
2024-01-29 08:47:36 +00:00
Chris Campbell
0d8fa6f490
Add $protected-branches to pull_request target
2024-01-26 09:03:10 +00:00
Chris Campbell
0239269003
Update to match standards in actions/starter-workflows/.../pull_request_template.md
2024-01-26 09:03:10 +00:00
Chris Campbell
aa49bd3095
Tidy up comments
2024-01-26 09:03:10 +00:00
Chris Campbell
11f5772f81
Update dependency-review.yml
2024-01-26 09:03:10 +00:00
Andrew Eisenberg and GitHub
42326d0804
Clarify permisions on codeql-action starter
2024-01-09 12:22:16 -08:00
4f4ef4e030
Synopsys Action's starter workflow ( #2234 )
...
* Synopsys action starter workflow
* Synopsys action - Address review comments
* Synopsys action - Address review comments 2
* Addressed review comments
* Fixed review comments
* Parameter changes accommodation
---------
Co-authored-by: kishorikumar <[email protected] >
Co-authored-by: Alexis Abril <[email protected] >
2023-12-22 12:11:56 -06:00
Nick Fyson and GitHub
3cb56ae6f3
update codeql.yml to reference node20 actions
2023-12-14 12:21:29 +00:00
Marco Gario and GitHub
d4b398cf2d
Include protected branches in PR analyses
2023-12-04 10:24:28 +01:00
16ea338f2a
fix: bearer does not upload sarif report ( #2178 )
...
* fix: bearer does not upload sarif report
When issues are found the exit code is non zero and so the github action aborts before uploading the sarif report.
This change fixes that issues.
* chore: update bearer.yml following review
---------
Co-authored-by: Cédric Fabianski <[email protected] >
Co-authored-by: Cédric Fabianski <[email protected] >
2023-11-22 16:01:57 -06:00
Isabelle and GitHub
c6c44522f3
Update to latest audit code version ( #2209 )
...
* Update to latest audit code version
* Fix Description
* Fix extra space in comments
2023-11-13 11:49:29 -06:00
David Verdeguer and GitHub
61f8558b81
Update codeql.yml
2023-10-03 07:40:34 +02:00
Cédric Fabianski
9744b8f3b5
feat: add Bearer code scanning option
2023-07-17 15:30:33 +02:00
James M. Greene and GitHub
0720e7f4d0
Merge branch 'main' into main
2023-07-13 11:00:22 -05:00
James M. Greene and GitHub
652258c72a
Bump frogbot to v2.10.0
2023-07-13 11:00:03 -05:00
James M. Greene and GitHub
257b26fcde
Merge branch 'main' into patch-3
2023-07-13 10:53:32 -05:00
James M. Greene and GitHub
f186f33e75
Merge branch 'main' into patch-4
2023-07-13 09:43:51 -05:00
James M. Greene and GitHub
ec351ca4a9
Delete trailing whitespace
2023-07-13 09:39:44 -05:00
James M. Greene and GitHub
bbb14beb4a
Merge branch 'main' into patch-2
2023-07-13 09:37:46 -05:00