diff --git a/.github/workflows/owasp-dependency-check.yml b/.github/workflows/owasp-dependency-check.yml new file mode 100644 index 0000000000..c7bfea49de --- /dev/null +++ b/.github/workflows/owasp-dependency-check.yml @@ -0,0 +1,27 @@ +# SPDX-FileCopyrightText: 2024 LibreCode coop and contributors +# SPDX-License-Identifier: AGPL-3.0-or-later + +name: "OWASP Dependency-Check" + +on: pull_request + +jobs: + dependency-check: + runs-on: ubuntu-latest + steps: + - name: Check out code + uses: actions/checkout@v2 + + - name: Run OWASP Dependency-Check + uses: dependency-check/gh-action@v4 + with: + format: 'ALL' + project: 'LibreSign' + scanPath: './' + failOnCVSS: '7.0' + + - name: Upload Dependency-Check report + uses: actions/upload-artifact@v4 + with: + name: dependency-check-report + path: dependency-check-report.html