comparison .github/workflows/anchore.yml @ 7485:e6cd3f3cd691

Bump actions/checkout from 3.5.2 to 3.5.3 - https://github.com/roundup-tracker/roundup/pull/37
author John Rouillard <rouilj@ieee.org>
date Sun, 11 Jun 2023 23:48:08 -0400
parents 010eb3b00877
children 0b4028a75705
comparison
equal deleted inserted replaced
7484:38ce0a2a9cf8 7485:e6cd3f3cd691
35 security-events: write # for github/codeql-action/upload-sarif to upload SARIF results 35 security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
36 actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status 36 actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
37 runs-on: ubuntu-latest 37 runs-on: ubuntu-latest
38 steps: 38 steps:
39 - name: Checkout the code 39 - name: Checkout the code
40 uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2 40 uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3.5.3
41 - name: Build the Docker image 41 - name: Build the Docker image
42 run: docker pull python:3-alpine; docker build . --file scripts/Docker/Dockerfile --tag localbuild/testimage:latest 42 run: docker pull python:3-alpine; docker build . --file scripts/Docker/Dockerfile --tag localbuild/testimage:latest
43 - name: List the Docker image 43 - name: List the Docker image
44 run: docker image ls 44 run: docker image ls
45 - name: Run the Anchore scan action itself with GitHub Advanced Security code scanning integration enabled 45 - name: Run the Anchore scan action itself with GitHub Advanced Security code scanning integration enabled

Roundup Issue Tracker: http://roundup-tracker.org/