Skip to content

Merge pull request #199 from guardian/an/gha-pin-ubuntu-2204 #215

Merge pull request #199 from guardian/an/gha-pin-ubuntu-2204

Merge pull request #199 from guardian/an/gha-pin-ubuntu-2204 #215

Workflow file for this run

name: Snyk
on:
push:
branches:
- main
workflow_dispatch:
jobs:
snyk-scala:
uses: guardian/.github/.github/workflows/sbt-node-snyk.yml@main
with:
DEBUG: true
ORG: guardian
SKIP_NODE: true
JAVA_VERSION: 8
EXCLUDE: package.json,package-lock.json # since we use the jspm workaround below
secrets:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
snyk-client:
uses: guardian/.github/.github/workflows/sbt-node-snyk.yml@main
with:
ORG: guardian
SKIP_SBT: true # exclude scala, since it's captured by the scala job above
NODE_PACKAGE_JSON_FILES_MISSING_LOCK: jspm-snyk-workaround/package.json jspm-snyk-workaround/result/package.json
secrets:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}