File tree Expand file tree Collapse file tree 3 files changed +11
-4
lines changed
Expand file tree Collapse file tree 3 files changed +11
-4
lines changed Original file line number Diff line number Diff line change 3030 PREDICTIVE_TEST_SELECTION : " ${{ github.event_name == 'pull_request' && 'true' || 'false' }}"
3131 SONAR_TOKEN : ${{ secrets.SONAR_TOKEN }}
3232 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
33+ OSS_INDEX_USERNAME : ${{ secrets.OSS_INDEX_USERNAME }}
34+ OSS_INDEX_PASSWORD : ${{ secrets.OSS_INDEX_PASSWORD }}
3335 steps :
3436 # https://github.com/actions/virtual-environments/issues/709
3537 - name : " 🗑 Free disk space"
5860 run : |
5961 [ -f ./setup.sh ] && ./setup.sh || [ ! -f ./setup.sh ]
6062
63+ - name : " 🚔 Sonatype Scan"
64+ id : sonatypescan
65+ run : |
66+ ./gradlew ossIndexAudit --no-parallel --info
67+
6168 - name : " 🛠 Build with Gradle"
6269 id : gradle
6370 run : |
Original file line number Diff line number Diff line change @@ -115,7 +115,7 @@ jobs:
115115 artifacts-sha256 : ${{ steps.set-hash.outputs.artifacts-sha256 }}
116116 steps :
117117 - name : Download artifacts-sha256
118- uses : actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
118+ uses : actions/download-artifact@95815c38cf2ff2164869cbab79da8d1f422bc89e # v4.2.1
119119 with :
120120 name : artifacts-sha256
121121 # The SLSA provenance generator expects the hash digest of artifacts to be passed as a job
@@ -148,7 +148,7 @@ jobs:
148148 - name : Checkout repository
149149 uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
150150 - name : Download artifacts
151- uses : actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
151+ uses : actions/download-artifact@95815c38cf2ff2164869cbab79da8d1f422bc89e # v4.2.1
152152 with :
153153 name : gradle-build-outputs
154154 path : build/repo
@@ -160,6 +160,6 @@ jobs:
160160 - name : Upload assets
161161 # Upload the artifacts to the existing release. Note that the SLSA provenance will
162162 # attest to each artifact file and not the aggregated ZIP file.
163- uses : softprops/action-gh-release@da05d552573ad5aba039eaac05058a918a7bf631 # v2.2.2
163+ uses : softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda # v2.2.1
164164 with :
165165 files : artifacts.zip
Original file line number Diff line number Diff line change 11distributionBase =GRADLE_USER_HOME
22distributionPath =wrapper/dists
3- distributionUrl =https\://services.gradle.org/distributions/gradle-8.13 -bin.zip
3+ distributionUrl =https\://services.gradle.org/distributions/gradle-8.14 -bin.zip
44networkTimeout =10000
55validateDistributionUrl =true
66zipStoreBase =GRADLE_USER_HOME
You can’t perform that action at this time.
0 commit comments