Skip to content

chore(deps): update module sigs.k8s.io/kustomize/kyaml to v0.18.1 - autoclosed #93

chore(deps): update module sigs.k8s.io/kustomize/kyaml to v0.18.1 - autoclosed

chore(deps): update module sigs.k8s.io/kustomize/kyaml to v0.18.1 - autoclosed #93

Workflow file for this run

name: Scan CVEs - Gosec
permissions:
contents: read
on:
push:
branches:
- main
pull_request:
branches:
- main
jobs:
tests:
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
env:
GO111MODULE: on
steps:
- name: Checkout Source
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
- name: Setup golang
uses: ./.github/actions/golang
- name: Install gosec
run: |
go install github.com/securego/gosec/v2/cmd/[email protected]
- name: Run Gosec Security Scanner
run: |
gosec -stdout -fmt sarif -out results.sarif ./...
- name: Upload artifact
uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4.4.3
with:
name: SARIF file
path: results.sarif
retention-days: 5
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@c36620d31ac7c881962c3d9dd939c40ec9434f2b # v3.26.12
with:
sarif_file: results.sarif