Files
my-rook-config/.github/workflows/synk.yaml
T
Sébastien Han d8e9885fd6 ci: only run snyk on merges and not on PRs
We cannot use the secret when PRs are pushed from forks so let's run the
security scan only after PRs are merged.

Signed-off-by: Sébastien Han <seb@redhat.com>
2021-10-26 10:55:43 +02:00

23 lines
401 B
YAML

name: Security scanning
on:
push:
tags:
- v*
branches:
- master
- release-*
jobs:
security:
runs-on: ubuntu-latest
steps:
- name: checkout
uses: actions/checkout@v2
with:
fetch-depth: 0
- name: run Snyk to check for code vulnerabilities
uses: snyk/actions/golang@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}