diff --git a/.github/workflows/_self-pull-request.yml b/.github/workflows/_self-pull-request.yml index ec9c5a2e..6e554bbb 100644 --- a/.github/workflows/_self-pull-request.yml +++ b/.github/workflows/_self-pull-request.yml @@ -23,8 +23,18 @@ jobs: with: args: --repo=https://github.com/${{github.repository}} - - name: 'Dependency Review' - uses: actions/dependency-review-action@v1 + - name: Run Trivy scanner + uses: aquasecurity/trivy-action@master + with: + scan-type: fs + format: 'sarif' + severity: 'CRITICAL,HIGH' + output: 'trivy-results.sarif' + + - name: Upload Trivy results + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: 'trivy-results.sarif' - name: Initialize CodeQL uses: github/codeql-action/init@v2 @@ -34,6 +44,9 @@ jobs: - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v2 + - name: 'Dependency Review' + uses: actions/dependency-review-action@v1 + Ossar-Analysis: runs-on: windows-latest diff --git a/.github/workflows/_self-push.yml b/.github/workflows/_self-push.yml index 47b6575d..a678ac01 100644 --- a/.github/workflows/_self-push.yml +++ b/.github/workflows/_self-push.yml @@ -32,7 +32,7 @@ jobs: output: 'trivy-results.sarif' - name: Upload Trivy results - uses: github/codeql-action/upload-sarif@v1 + uses: github/codeql-action/upload-sarif@v2 with: sarif_file: 'trivy-results.sarif'