ci(security): include photon sidecar + whatsapp bridge lockfiles in OSV scan
Surgical reapply of PR #46747 by @tank321 onto the current reusable-workflow form of osv-scanner.yml (the original targeted the old direct-action layout). Fixes #46738.
This commit is contained in:
4
.github/workflows/osv-scanner.yml
vendored
4
.github/workflows/osv-scanner.yml
vendored
@@ -43,11 +43,13 @@ jobs:
|
||||
uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8
|
||||
with:
|
||||
# Scan explicit lockfiles rather than recursing, so we only look at
|
||||
# the three sources of truth and skip vendored / test / worktree dirs.
|
||||
# the five sources of truth and skip vendored / test / worktree dirs.
|
||||
scan-args: |-
|
||||
--lockfile=uv.lock
|
||||
--lockfile=package-lock.json
|
||||
--lockfile=website/package-lock.json
|
||||
--lockfile=plugins/platforms/photon/sidecar/package-lock.json
|
||||
--lockfile=scripts/whatsapp-bridge/package-lock.json
|
||||
# The upstream reusable workflow uploads this exact file under its
|
||||
# fixed artifact name, which the wrapper downloads below.
|
||||
results-file-name: osv-results.sarif
|
||||
|
||||
1
contributors/emails/mromano3@ad.engr.wisc.edu
Normal file
1
contributors/emails/mromano3@ad.engr.wisc.edu
Normal file
@@ -0,0 +1 @@
|
||||
tank321
|
||||
Reference in New Issue
Block a user