-
Notifications
You must be signed in to change notification settings - Fork 0
27 lines (27 loc) · 1.18 KB
/
Copy pathsecurity-scan.yml
File metadata and controls
27 lines (27 loc) · 1.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
name: security-scan (on demand)
on:
workflow_dispatch:
inputs:
address: { description: "Contract address (must be verified on Sourcify)", required: true }
chain_id: { description: "Chain ID", required: true, default: "1" }
name: { description: "Display name", required: false }
permissions: { contents: write }
concurrency: { group: hub-data, cancel-in-progress: false }
jobs:
scan:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with: { python-version: "3.12" }
- run: pip install -q slither-analyzer==0.11.6 solc-select
- name: validate input
run: |
[[ "$ADDR" =~ ^0x[0-9a-fA-F]{40}$ ]] || { echo "bad address"; exit 1; }
[[ "$CHAIN" =~ ^[0-9]+$ ]] || { echo "bad chain"; exit 1; }
env: { ADDR: "${{ inputs.address }}", CHAIN: "${{ inputs.chain_id }}" }
- run: python scripts/job_slither.py "$CHAIN" "$ADDR" "$NAME"
env: { ADDR: "${{ inputs.address }}", CHAIN: "${{ inputs.chain_id }}", NAME: "${{ inputs.name }}" }
- run: 'scripts/commit.sh "data: on-demand scan $ADDR"'
env: { ADDR: "${{ inputs.address }}" }