Skip to content

Update dependency ch.qos.logback:logback-core to v1.5.13 [SECURITY] #174

Update dependency ch.qos.logback:logback-core to v1.5.13 [SECURITY]

Update dependency ch.qos.logback:logback-core to v1.5.13 [SECURITY] #174

name: CVE Scanning for Maven
defaults:
run:
shell: bash
working-directory: setup
on:
workflow_dispatch:
push:
paths:
- '**/pom.xml'
- 'allow-list.xml'
- '.github/workflows/cve-scanning.yml'
pull_request:
paths:
- 'pom.xml'
- 'allow-list.xml'
- '.github/workflows/cve-scanning.yml'
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up JDK 17
uses: actions/setup-java@v3
with:
java-version: '17'
distribution: 'temurin'
cache: maven
- name: Build with Maven
run: mvn clean install -DskipTests
- name: CVE scanning
run: mvn org.owasp:dependency-check-maven:check -DfailBuildOnCVSS=7 -DsuppressionFile="allow-list.xml"