mirror of
https://github.com/GSA/notifications-api.git
synced 2026-09-07 10:18:26 -04:00
run pip-audit only on production code
This commit is contained in:
@@ -151,7 +151,7 @@
|
|||||||
"filename": ".github/workflows/daily_checks.yml",
|
"filename": ".github/workflows/daily_checks.yml",
|
||||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||||
"is_verified": false,
|
"is_verified": false,
|
||||||
"line_number": 65,
|
"line_number": 64,
|
||||||
"is_secret": false
|
"is_secret": false
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -159,7 +159,7 @@
|
|||||||
"filename": ".github/workflows/daily_checks.yml",
|
"filename": ".github/workflows/daily_checks.yml",
|
||||||
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
|
||||||
"is_verified": false,
|
"is_verified": false,
|
||||||
"line_number": 81,
|
"line_number": 80,
|
||||||
"is_secret": false
|
"is_secret": false
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
@@ -374,5 +374,5 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"generated_at": "2026-03-26T17:07:05Z"
|
"generated_at": "2026-03-26T17:19:11Z"
|
||||||
}
|
}
|
||||||
|
|||||||
3
.github/workflows/daily_checks.yml
vendored
3
.github/workflows/daily_checks.yml
vendored
@@ -26,14 +26,13 @@ jobs:
|
|||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- uses: ./.github/actions/setup-project
|
- uses: ./.github/actions/setup-project
|
||||||
- name: Create requirements.txt
|
- name: Create requirements.txt
|
||||||
# Currently there is an unresolved vulnerability in 2.19.2 of pygments
|
|
||||||
# which is used by pytest. Ignore dev dependencies vulnerabilities for now
|
|
||||||
run: poetry export --only main --output requirements.txt
|
run: poetry export --only main --output requirements.txt
|
||||||
- uses: pypa/gh-action-pip-audit@v1.1.0
|
- uses: pypa/gh-action-pip-audit@v1.1.0
|
||||||
with:
|
with:
|
||||||
inputs: requirements.txt
|
inputs: requirements.txt
|
||||||
ignore-vulns: |
|
ignore-vulns: |
|
||||||
PYSEC-2023-312
|
PYSEC-2023-312
|
||||||
|
CVE-2026-4539
|
||||||
- name: Upload pip-audit artifact
|
- name: Upload pip-audit artifact
|
||||||
uses: actions/upload-artifact@v4
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
Reference in New Issue
Block a user