-
Notifications
You must be signed in to change notification settings - Fork 281
87 lines (76 loc) · 2.85 KB
/
Copy pathjava-security.yml
File metadata and controls
87 lines (76 loc) · 2.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
name: Java Dependency Security
on:
workflow_call:
secrets:
NVD_API_KEY:
description: Optional NVD API key used to accelerate OWASP Dependency-Check updates
required: false
workflow_dispatch: { }
permissions:
contents: read
jobs:
java-dependency-scan:
name: Scan Java runtime dependencies
runs-on: ubuntu-24.04
timeout-minutes: 60
concurrency:
group: java-dependency-security
cancel-in-progress: false
env:
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
persist-credentials: false
- uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9
with:
java-version: '17'
distribution: 'temurin'
cache: 'maven'
- name: Restore vulnerability database
id: dependency-check-cache
uses: actions/cache/restore@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
with:
path: ~/.m2/repository/org/owasp/dependency-check-data
key: ${{ runner.os }}-dependency-check-${{ github.run_id }}-${{ github.run_attempt }}
restore-keys: |
${{ runner.os }}-dependency-check-
- name: Remove stale vulnerability database lock
run: |
data_dir="${HOME}/.m2/repository/org/owasp/dependency-check-data"
if [[ -d "${data_dir}" ]]; then
find "${data_dir}" -type f -name 'odc.update.lock' -delete
fi
- name: Scan Java runtime dependencies
run: |
nvd_options=()
if [[ -z "${NVD_API_KEY}" ]]; then
# Anonymous NVD access is slower and subject to a lower rate limit.
nvd_options=(-DnvdApiDelay=10000 -DnvdMaxRetryCount=20)
fi
./mvnw verify -Psecurity-scan \
-DskipTests \
-Dcheckstyle.skip=true \
"${nvd_options[@]}" \
-B -V --no-transfer-progress
- name: Remove vulnerability database lock before caching
if: always()
run: |
data_dir="${HOME}/.m2/repository/org/owasp/dependency-check-data"
if [[ -d "${data_dir}" ]]; then
find "${data_dir}" -type f -name 'odc.update.lock' -delete
fi
- name: Save vulnerability database
if: always()
uses: actions/cache/save@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
with:
path: ~/.m2/repository/org/owasp/dependency-check-data
key: ${{ steps.dependency-check-cache.outputs.cache-primary-key }}
- name: Upload dependency reports
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: compileflow-java-dependency-reports
path: '**/target/dependency-check-report.*'
if-no-files-found: warn
retention-days: 14