Carlo Costino
34cc85e662
Update GitHub Actions
...
This changeset updates all references to GitHub Actions to be version 4 due to a mandatory Node.js update.
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov >
2024-04-04 08:35:00 -04:00
Carlo Costino
e019e9cf11
Update OWASP ZAP scans
...
The OWASP ZAP scan GitHub Actions have been updated recently and we need to make sure our GitHub Actions account for the recent changes. This changeset makes sure we are using the latest version of the OWASP ZAP API scan, the correct Docker image, and adjusts the name of the step to accurately reflect what scan is being run.
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov >
2023-09-28 17:28:27 -04:00
Kenneth Kehl
722b67e93a
try without hashes
2023-08-31 11:43:33 -07:00
Kenneth Kehl
062675ad9b
poetry
2023-08-31 11:00:55 -07:00
stvnrlly
9bda30394d
try updating docker action version?
2023-08-02 16:07:15 -04:00
stvnrlly
a99c01eb14
move checks to daily run only
2023-07-11 21:35:15 -04:00
stvnrlly
f8d23f8c45
try to create pip-audit artifact in daily test
2023-07-11 17:19:07 -04:00
Steven Reilly
6515c44ca8
bump pip-audit action to 1.0.6 ( #261 )
2023-05-05 14:11:18 -04:00
Ryan Ahearn
6118394f02
Remove ignore-vulnerability for remediated redis vuln
2023-03-29 17:04:43 -04:00
Ryan Ahearn
8e64fb12ba
Ignore known issue with redis 4.5.3
2023-03-28 09:06:21 -04:00
Ryan Ahearn
84e7e9b5cf
Use credentials output by terraform/development
2023-03-13 13:44:10 -04:00
Ryan Ahearn
36975dda07
Ensure CI runs have proper phone number format
2023-03-03 14:13:58 -05:00
Ryan Ahearn
28f8649444
Use sns credentials from VCAP_SERVICES
2023-02-28 16:50:00 -05:00
Ryan Ahearn
cdf2810b14
Update flask & cryptography versions
2023-02-09 17:26:36 -05:00
Ryan Ahearn
b9a53b7b54
Validate new relic config in github actions
2023-01-19 09:33:33 -05:00
Ryan Ahearn
bec3c53128
Setup newrelic for cloud.gov environments
2023-01-18 09:20:22 -05:00
Ryan Ahearn
7e02e6b33d
Update to most recent pip-audit action
2023-01-03 09:44:53 -05:00
Ryan Ahearn
7c611e993f
Read openapi schema for the owasp scan
2022-11-16 15:50:08 -05:00
Ryan Ahearn
7aafdd7bac
Clean up config settings
2022-10-31 13:25:59 -04:00
stvnrlly
d87c224473
remove broadcast-related code, except migrations
2022-10-26 16:41:35 -04:00
stvnrlly
2889f6220a
actually write requirements to file
2022-10-26 16:21:45 -04:00
stvnrlly
d27401c7a0
more pipenv transition
2022-10-26 14:05:37 +00:00
stvnrlly
d4e156e8ae
Merge branch 'main' into stvnrlly-remove-broadcasts
2022-10-20 19:44:20 -04:00
Ryan Ahearn
cd7da37fa9
Only run pip-audit on runtime dependencies in CI
2022-10-19 10:09:09 -04:00
stvnrlly
57f4df8ed1
remove broadcast-related code, except migrations
2022-10-04 15:28:27 +00:00
Ryan Ahearn
e3ad01119d
Replace celery[sqs] with celery[redis]
2022-09-29 08:59:17 -04:00
Ryan Ahearn
2550464b8f
Run scans every day
2022-08-23 16:44:34 -04:00