Merge pull request #23 from puppetlabs/snyk_scan

(DIO-3134) Scan repo with Snyk
This commit is contained in:
Samuel 2022-05-04 14:38:30 -05:00 committed by GitHub
commit 5d04a41003
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

23
.github/workflows/snyk_scan.yaml vendored Normal file
View file

@ -0,0 +1,23 @@
name: Snyk Scan
on:
workflow_dispatch:
push:
branches:
- master
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@master
- name: setup ruby
uses: ruby/setup-ruby@v1
with:
ruby-version: 2.7
- name: create lock
run: bundle lock
- name: Run Snyk to check for vulnerabilities
uses: snyk/actions/ruby@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_DIO_KEY }}
with:
command: monitor