ci: add a weekly NVD-based deep CVE audit #5
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: cve-scan | |
| on: | |
| pull_request: | |
| workflow_dispatch: | |
| jobs: | |
| cve-scan: | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5 | |
| with: | |
| distribution: 'temurin' | |
| java-version: '21' | |
| - name: Set up Workspace Environment Variable | |
| run: echo "WORKSPACE=${{ github.workspace }}" >> $GITHUB_ENV | |
| - name: Restore Maven dependency cache | |
| # Restore-only: PR scopes cannot share caches with each other, so per-PR | |
| # saves are dead weight that evicts the useful master-scoped caches | |
| # (10 GB repo budget). The producer is snapshot.yml on master pushes | |
| # (Linux-maven-publish-*). Path and key must mirror snapshot.yml exactly: | |
| # the literal path spec is hashed into the cache *version*, so any | |
| # variation (~/.m2 vs /home/runner/.m2) makes its caches unmatchable. | |
| uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: ~/.m2/repository | |
| key: ${{ runner.os }}-maven-publish-${{ hashFiles('**/pom.xml', '**/*.target') }} | |
| restore-keys: ${{ runner.os }}-maven-publish- | |
| - name: Check dependencies for known CVEs | |
| run: bash .github/scripts/check-cves.sh | |
| - name: Archive SBOM and scan results | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: cve-scan-results | |
| path: | | |
| ddk-parent/target/bom.json | |
| ddk-parent/target/cve-scan/ | |
| retention-days: 30 |