diff --git a/.github/actions/setup/action.yml b/.github/actions/setup/action.yml index 98e09c7..c3c163c 100644 --- a/.github/actions/setup/action.yml +++ b/.github/actions/setup/action.yml @@ -5,7 +5,7 @@ inputs: java: description: The Java version to use required: false - default: 8.0.382-tem + default: 11 gradle: description: The Gradle version to use required: false @@ -19,11 +19,14 @@ runs: using: composite steps: + - uses: actions/setup-java@v4 + with: + distribution: temurin + java-version: ${{ inputs.java }} + - run: | curl -s "https://get.sdkman.io" | bash - source "/home/runner/.sdkman/bin/sdkman-init.sh" - sdk list java - sdk install java ${{ inputs.java }} && sdk default java ${{ inputs.java }} + source "$HOME/.sdkman/bin/sdkman-init.sh" sdk install gradle ${{ inputs.gradle }} && sdk default gradle ${{ inputs.gradle }} sdk install kotlin ${{ inputs.kotlin }} && sdk default kotlin ${{ inputs.kotlin }} shell: bash diff --git a/.github/workflows/sca_scan.yml b/.github/workflows/sca_scan.yml index 3cf3add..1aeecee 100644 --- a/.github/workflows/sca_scan.yml +++ b/.github/workflows/sca_scan.yml @@ -2,10 +2,11 @@ name: SCA on: pull_request: - branches: ["master"] workflow_dispatch: jobs: snyk-cli: uses: auth0/devsecops-tooling/.github/workflows/sca-scan.yml@main + with: + java-version: "11" secrets: inherit diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml deleted file mode 100644 index 0cdf000..0000000 --- a/.github/workflows/snyk.yml +++ /dev/null @@ -1,40 +0,0 @@ -name: Snyk - -on: - merge_group: - workflow_dispatch: - pull_request: - types: - - opened - - synchronize - push: - branches: - - master - schedule: - - cron: "30 0 1,15 * *" - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: ${{ github.ref != 'refs/heads/master' }} - -jobs: - check: - name: Check for Vulnerabilities - runs-on: ubuntu-latest - - steps: - - if: github.actor == 'dependabot[bot]' || github.event_name == 'merge_group' - run: exit 0 # Skip unnecessary test runs for dependabot and merge queues. Artifically flag as successful, as this is a required check for branch protection. - - - uses: actions/checkout@v4 - with: - ref: ${{ github.event.pull_request.head.sha || github.ref }} - - - run: npm install snyk -g - - - run: snyk test - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} diff --git a/build.gradle b/build.gradle index 3a20404..1764108 100644 --- a/build.gradle +++ b/build.gradle @@ -1,12 +1,12 @@ buildscript { repositories { google() + mavenCentral() jcenter() } dependencies { classpath 'com.android.tools.build:gradle:3.6.1' - classpath 'com.jfrog.bintray.gradle:gradle-bintray-plugin:1.8.4' } } @@ -19,6 +19,7 @@ allprojects { repositories { google() + mavenCentral() jcenter() } }