-
Notifications
You must be signed in to change notification settings - Fork 29
58 lines (53 loc) · 1.82 KB
/
endorlabs.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
name: Endor Labs Scan Test
on:
workflow_dispatch:
inputs:
api:
description: "Enter the target Endor Labs API"
required: true
type: choice
default: https://api.endorlabs.com
options:
- https://api.staging.endorlabs.com
- https://api.endorlabs.com
tenant_name:
description: "Enter your Endor Labs namespace?"
required: true
type: string
jobs:
scan-repo:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
steps:
- name: Setup namespace Environment Variables
run: |
NAMESPACE=$(jq -r '.inputs.tenant_name' $GITHUB_EVENT_PATH)
echo "::add-mask::$NAMESPACE"
echo NAMESPACE=$NAMESPACE >> $GITHUB_ENV
echo ENDOR_JS_ENABLE_TSSERVER=true >> $GITHUB_ENV
- name: Checkout Repository
uses: actions/checkout@v3
- name: Setup Java
uses: actions/setup-java@v4
with:
distribution: microsoft
java-version: "17"
cache: maven
cache-dependency-path: pom.xml
- name: Compile Package
run: mvn clean install
- name: Endor Labs Call Graph Generation
if: ${{ github.event_name == 'workflow_dispatch' }}
uses: endorlabs/github-action@e4ee275237b23c0071efa2e3966654ee64880a90
with:
namespace: ${{ github.event.inputs.tenant_name }}
scan_summary_output_type: "table"
# pr: "false"
enable_github_action_token: "true"
scan_dependencies: "true"
log_level: "debug"
# scan_secrets: "true"
# scan_git_logs: "true"
additional_args: "--call-graph-languages=javascript,typescript >> json.txt & cat json.txt"