Skip to content

Updated logback (#395) #43

Updated logback (#395)

Updated logback (#395) #43

name: Vulnerability scan
on:
push:
branches:
- master
- main
workflow_dispatch:
jobs:
security:
runs-on:
group: organization/Default
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Run Snyk monitor for vulnerabilities
uses: snyk/actions/gradle-8-jdk21@9adf32b1121593767fc3c057af55b55db032dc04 # master
env:
SNYK_TOKEN: ${{ secrets.SNYK_SDK_TOKEN }}
# Snyk Gradle actions run in a container; inheriting the runner's JAVA_HOME
# (e.g., /opt/hostedtoolcache/...) can break inside the container because that
# path is not present there. Ensure Gradle uses the container-provided JDK.
JAVA_HOME: ""
JAVA_HOME_21_X64: ""
JAVA_HOME_21_ARM64: ""
with:
command: monitor
args: --org=sdk --all-sub-projects