ci(security): include photon sidecar + whatsapp bridge lockfiles in OSV scan

Surgical reapply of PR #46747 by @tank321 onto the current reusable-workflow
form of osv-scanner.yml (the original targeted the old direct-action layout).
Fixes #46738.
This commit is contained in:
mromano3
2026-07-28 22:38:29 -07:00
committed by Teknium
parent 9704ed86c1
commit f21332f073
2 changed files with 4 additions and 1 deletions

View File

@@ -43,11 +43,13 @@ jobs:
uses: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8
with:
# Scan explicit lockfiles rather than recursing, so we only look at
# the three sources of truth and skip vendored / test / worktree dirs.
# the five sources of truth and skip vendored / test / worktree dirs.
scan-args: |-
--lockfile=uv.lock
--lockfile=package-lock.json
--lockfile=website/package-lock.json
--lockfile=plugins/platforms/photon/sidecar/package-lock.json
--lockfile=scripts/whatsapp-bridge/package-lock.json
# The upstream reusable workflow uploads this exact file under its
# fixed artifact name, which the wrapper downloads below.
results-file-name: osv-results.sarif

View File

@@ -0,0 +1 @@
tank321