Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
154 commits
Select commit Hold shift + click to select a range
10533e0
Update pom.xml
jwaizguy Aug 7, 2022
ee95caa
Update pom.xml
jwaizguy Aug 7, 2022
c979435
Add files via upload
jwaizguy Aug 7, 2022
34d7008
Add files via upload
jwaizguy Aug 7, 2022
9e846f8
Set up CI with Azure Pipelines
jwaizguy Aug 10, 2022
35ba38e
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
49eaee8
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
a1fe52f
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
aaba092
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
0a581e4
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
64cf01e
Set up CI with Azure Pipelines
jwaizguy Aug 10, 2022
5bafcd9
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
eea52f6
Set up CI with Azure Pipelines
jwaizguy Aug 10, 2022
51654eb
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
fdbf6c6
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
1e3c7e1
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
e534861
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
dfdbdca
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
219e564
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Aug 10, 2022
4473c8f
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
26c4ec5
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
0b396b5
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
0182073
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 10, 2022
4ad0d40
Update azure-pipelines.yml
jwaizguy Oct 24, 2022
2b95e5f
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Oct 27, 2022
cd67f44
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Oct 27, 2022
b9c8c75
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Oct 27, 2022
426f946
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Oct 27, 2022
2e82275
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Oct 27, 2022
c514814
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Oct 27, 2022
ce38f1f
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Oct 27, 2022
1ea3f74
Set up CI with Azure Pipelines PolarisNXGN
jwaizguy Nov 1, 2022
bd993fd
Update blackduck.yml
jwaizguy Nov 21, 2022
9741b55
Add workflow file
jwaizguy Feb 7, 2023
9902c83
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Jul 19, 2023
b68aa25
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Jul 20, 2023
e31a7d1
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Jul 20, 2023
b2bfb43
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Jul 20, 2023
b3be90c
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Jul 20, 2023
b8e6c2a
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 9, 2023
537d90b
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 9, 2023
e69504f
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 9, 2023
0177eea
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 9, 2023
a3b9fdb
Update azure-pipelines.yml
jwaizguy Aug 9, 2023
9e28b77
Update azure-pipelines.yml
jwaizguy Aug 9, 2023
6648746
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Aug 9, 2023
26cc808
Update azure-pipelines.yml
jwaizguy Aug 12, 2023
6c06089
Update azure-pipelines.yml for Azure Pipelines
jwaizguy Nov 22, 2023
385f1f3
Update Jenkinsfile
jwaizguy Nov 30, 2023
790a097
Update Jenkinsfile
jwaizguy Nov 30, 2023
b96c1e1
Update ForwardNullExample.java
jwaizguy Nov 30, 2023
bf9f413
Update HelloWorld.java
jwaizguy Nov 30, 2023
be657d1
Set up CI with Azure Pipelines
jwaizguy Feb 6, 2024
29c5baf
Update azure-pipelines-2.yml
jwaizguy Feb 6, 2024
d69d7c1
Create jose.yml
jwaizguy Feb 6, 2024
a09cad5
Create main.yml
jwaizguy Feb 6, 2024
ed9e227
Update main.yml
jwaizguy Feb 6, 2024
476f21c
Update main.yml
jwaizguy Feb 6, 2024
69a8e7e
Update main.yml
jwaizguy Feb 6, 2024
f4a8bf5
Create SECURITY.md
jwaizguy Feb 6, 2024
17d4458
Update main.yml
jwaizguy Feb 6, 2024
7365b80
Update main.yml
jwaizguy Feb 6, 2024
3da9582
Update main.yml
jwaizguy Feb 6, 2024
c08f55c
Create coverity.yml
jwaizguy Feb 6, 2024
10ab1b2
Create synopsys-action2.yml
jwaizguy Feb 6, 2024
0f55b0f
Update pom.xml
jwaizguy Feb 6, 2024
cccab00
Update pom.xml
jwaizguy Feb 6, 2024
4f659e6
Update pom.xml
jwaizguy Feb 6, 2024
0f4055a
Update main.yml
jwaizguy Feb 6, 2024
bbf55d1
Delete .github/workflows/jose.yml
jwaizguy Feb 6, 2024
32dcf92
Update main.yml
jwaizguy Feb 6, 2024
fc9e666
Update main.yml
jwaizguy Feb 6, 2024
f4fe3a2
Update pom.xml
jwaizguy Feb 6, 2024
4c9f684
Update pom.xml
jwaizguy Feb 6, 2024
e959e99
Merge pull request #3 from jwaizguy/jwaizguy-patch-1
jwaizguy Feb 6, 2024
34039ae
Update main.yml
jwaizguy Feb 6, 2024
412abb4
Update main.yml
jwaizguy Feb 6, 2024
168db8f
Update main.yml
jwaizguy Mar 19, 2024
c0bf9c7
Update main.yml
jwaizguy Mar 19, 2024
5fa4b2e
Update synopsys-action2.yml
jwaizguy Mar 19, 2024
1a83afc
Update pom.xml
jwaizguy Mar 19, 2024
4c88a44
Create synopsys-action.yml
jwaizguy Mar 19, 2024
cbca965
Update SynopsysDetect.yaml
jwaizguy Mar 19, 2024
1d5dc7f
Update pom.xml
jwaizguy Mar 20, 2024
8972cb7
Update main.yml
jwaizguy Mar 20, 2024
bf4da39
demo.yml
jwaizguy Apr 3, 2024
88f6740
Create demo.yml
jwaizguy Apr 3, 2024
276f268
Create synopsys-action3.yml
jwaizguy Apr 3, 2024
771facd
Update demoyml
jwaizguy Apr 3, 2024
24777b2
Update demo.yml
jwaizguy Apr 4, 2024
14851d3
Update demo.yml
jwaizguy Apr 4, 2024
a21c8e4
Create synopsys-sec.yml
jwaizguy Apr 4, 2024
c7c44d3
Update synopsys-sec.yml
jwaizguy Apr 4, 2024
21e2be1
Update synopsys-sec.yml
jwaizguy Apr 4, 2024
1591e2d
Update synopsys-sec.yml
jwaizguy Apr 4, 2024
2a4370f
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
5938226
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
25afc50
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
9c0c71e
Update demoyml
jwaizguy Apr 4, 2024
3b2ad67
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
3026336
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
25d804f
Update SynopsysDetect.yaml
jwaizguy Apr 4, 2024
f76ed39
Update synopsys-action.yml
jwaizguy Apr 25, 2024
eff98c4
Update azure-pipelines.yml
jwaizguy Apr 25, 2024
2417ea1
Update azure-pipelines.yml
jwaizguy Apr 25, 2024
6961fe7
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
2bfc582
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
edcfbbd
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
4bcbd5b
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
0d783dd
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
43e23af
Update azure-pipelines-2.yml for Azure Pipelines
jwaizguy Jul 12, 2024
42b7594
Update azure-pipelines-1.yml for Azure Pipelines
jwaizguy Jul 12, 2024
02a6cf7
Update demo.yml
jwaizguy Aug 26, 2024
2e47faf
Update demo.yml
jwaizguy Aug 27, 2024
8c66987
Update demo.yml
jwaizguy Aug 27, 2024
c011cc8
Update demo.yml
jwaizguy Aug 27, 2024
a010ee8
Update demo.yml
jwaizguy Aug 27, 2024
4545887
Update demo.yml
jwaizguy Aug 27, 2024
095ff15
Create BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
e33b5a4
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
9ecae5a
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
6ca6857
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
32e62f8
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
04ac8cf
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
5c70cab
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
fa28439
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
57c7d7f
Update BitBucket-Polaris.yml
jwaizguy Aug 28, 2024
6cc3b61
Update demo.yml
jwaizguy Sep 3, 2024
b4cc33c
Update demo.yml
jwaizguy Sep 4, 2024
05d0117
Update BitBucket-Polaris.yml
jwaizguy Sep 4, 2024
1599a3b
Update synopsys-action.yml
jwaizguy Nov 19, 2024
7659ea6
Update synopsys-action.yml
jwaizguy Jan 16, 2025
eb7e1da
Update synopsys-action.yml
jwaizguy Jan 16, 2025
40e85b5
Update synopsys-action.yml
jwaizguy Jan 16, 2025
dfca2ca
Create Blackduck-Polaris.yml
jwaizguy Jan 16, 2025
6d62d6c
Update Blackduck-Polaris.yml
jwaizguy Jan 16, 2025
170c612
Create Class1.yml
jwaizguy Jan 17, 2025
b37e917
Update synopsys-action.yml
jwaizguy May 19, 2025
135b06e
Update Class1.yml
jwaizguy May 19, 2025
2c76181
Update synopsys-action.yml
jwaizguy May 19, 2025
39577ba
Update Class1.yml
jwaizguy May 19, 2025
b72419f
Update Class1.yml
jwaizguy May 19, 2025
c39a139
Update Class1.yml
jwaizguy May 19, 2025
36c13de
Update Class1.yml
jwaizguy May 19, 2025
2089752
Update Class1.yml
jwaizguy May 19, 2025
cf8d458
Update Class1.yml
jwaizguy May 20, 2025
65f4bbc
Update Class1.yml
jwaizguy May 20, 2025
4ebac0e
Update Class1.yml
jwaizguy May 20, 2025
1e69345
Update Class1.yml
jwaizguy May 20, 2025
eb7386a
Update Class1.yml
jwaizguy May 20, 2025
90c66c6
Update Class1.yml
jwaizguy May 20, 2025
85087d0
Update Class1.yml
jwaizguy May 20, 2025
abc5778
Update Class1.yml
jwaizguy May 20, 2025
454a7fa
Update pom.xml
jwaizguy May 22, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 42 additions & 0 deletions .github/workflows/BitBucket-Polaris.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: CI-Polaris-
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: checkout-bitbucket
run: git clone https://[email protected]/jwpolaris/hello-java.git
- name: Setup Java JDK
uses: actions/setup-java@v4
with:
java-version: 11
distribution: microsoft
cache: maven
- name: Polaris Scan
uses: synopsys-sig/[email protected]
env:
DETECT_DETECTOR_SEARCH_DEPTH: 10
with:
### SCANNING: Required fields
polaris_server_url: ${{ vars.POLARIS_SERVERURL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"


### SCANNING: Optional fields
polaris_application_name: AJW-${{ github.event.repository.name }}
# polaris_project_name: ${{ github.event.repository.name }}

### PULL REQUEST COMMENTS: Uncomment below to enable
polaris_prComment_enabled: true
github_token: ${{ secrets.GITHUB_TOKEN }} # Required when PR comments is enabled

### SARIF report parameters
polaris_reports_sarif_create: true
polaris_upload_sarif_report: true
44 changes: 44 additions & 0 deletions .github/workflows/Blackduck-Polaris.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: CI-Polaris-Basic
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: Checkout Source
uses: actions/checkout@v4
- name: Setup Java JDK
uses: actions/setup-java@v4
with:
java-version: 17
distribution: microsoft
cache: maven
- name: NEW Polaris Scan 1
uses: blackduck-inc/[email protected]
with:
### SCANNING: Required fields
polaris_server_url: ${{ secrets.POLARIS_SERVER_URL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"
polaris_application_name: "JWtest"
polaris_project_name: "hello-java"
polaris_branch_name: "main41"


### PULL REQUEST COMMENTS: Uncomment below to enable
# polaris_prComment_enabled: ${{ github.event_name == 'pull_request' && 'true' || 'false' }}
#polaris_prComment_enabled: true
#github_token: ${{ secrets.git_pat }} # Required when PR comments is enabled

#- name: Save Logs
# if: always()
# uses: actions/upload-artifact@v3
# with:
# name: bridge-logs
#path: ${{ github.workspace }}/.bridge/**/*.json

98 changes: 98 additions & 0 deletions .github/workflows/Class1.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
# This workflow will build a Java project with Maven, and cache/restore any dependencies to improve the workflow execution time
# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-java-with-maven

# This workflow uses actions that are not certified by GitHub what a pitty
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.

name: Java CI with Maven

on:
push:
branches: [ "main", "jw*.*" ]
pull_request:
branches: [ "main", "jw*.*" ]

jobs:
build:

runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4
- name: Set up JDK 17
uses: actions/setup-java@v4
with:
java-version: '17'
distribution: 'temurin'
cache: maven
- name: Black Duck Security Scan
uses: blackduck-inc/[email protected]
with:
# Specifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.
# coverity_waitForScan: # optional
# Build command for Coverity
# coverity_build_command: # optional
# Clean command for Coverity
# coverity_clean_command: # optional
# Coverity config file path (.yaml/.yml/.json)
# If provided, Black Duck Security Action will download specific version of coverity thin client to use.
#bridge_coverity_version: # optional
polaris_server_url: ${{ secrets.POLARIS_SERVER_URL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA"
polaris_application_name: "JoseWaizman2"
polaris_project_name: "hello-java"
polaris_branch_name: "jw-13"
# Flag to enable pull request comments based on Polaris scan result
polaris_prComment_enabled: "true"
github_token: ${{ secrets.GITHUB_TOKEN }}
# List of severities for which the PR Comments should be created
polaris_prComment_severities: "CRITICAL,HIGH,MEDIUM,LOW"
# Polaris parent branch name
polaris_branch_parent_name: main
# Polaris test type to trigger signature scan or package manager scan
polaris_test_sca_type: "SCA-SIGNATURE"
# Flag to enable/disable Polaris SARIF report generation
polaris_reports_sarif_create: yes
# File path including file name where Polaris SARIF report should be created
# polaris_reports_sarif_file_path: # optional
# Indicates what SAST/SCA issues severity categories to include in Polaris SARIF file report
polaris_reports_sarif_severities: "CRITICAL,HIGH,MEDIUM,LOW"
# Flag to enable/disable Component-Version grouping for SCA Issues in Polaris SARIF report rules section
# polaris_reports_sarif_groupSCAIssues: # optional
# Enum to indicate which assessment issues type to include in Polaris SARIF file report
# polaris_reports_sarif_issue_types: "SAST,SCA"
# Flag to enable/disable uploading of Polaris SARIF report to GitHub Advanced Security
polaris_upload_sarif_report: yes
# Specifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.
# polaris_waitForScan: # optional
# The test mode type of this scan
# polaris_assessment_mode: # optional
# The project source directory. Defaults to repository root directory. Set this to specify a custom folder that is other than repository root
# project_directory: # optional
# The zipped source file path. It overrides the project directory setting
# project_source_archive: # optional
# Flag indicating whether to preserve symlinks in the source zip
# project_source_preserveSymLinks: # optional
# A list of git ignore pattern strings that indicate the files need to be excluded from the zip file
# project_source_excludes: # optional
# Bridge CLI Install Directory
# bridgecli_install_directory: # optional
# URL to download bridge from
# bridgecli_download_url: # optional
# Github token to be used for git related rest operation
# github_token: # optional
# To include diagnostics info and export as zip
include_diagnostics: no
# Number of days to keep the diagnostics files downloadable
#diagnostics_retention_days: # optional
# To enable creation of badges on the GitHub repository for polaris
polaris_policy_badges_create: yes
# To limit number of badges to be displayed on the GitHub repository for polaris
# polaris_policy_badges_maxCount: # optional
# Specify the build status if policy violating issues are found.
#mark_build_status: "success"


44 changes: 44 additions & 0 deletions .github/workflows/SynopsysDetect.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: CI-Polaris-Basic
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: Checkout Source
uses: actions/checkout@v4
- name: NEW Polaris Scan 1
uses: synopsys-sig/[email protected]
with:
### SCANNING: Required fields
polaris_server_url: ${{ secrets.POLARIS_SERVER_URL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"
polaris_application_name: "JWtest"
polaris_project_name: "HelloJava"


### PULL REQUEST COMMENTS: Uncomment below to enable
#polaris_prComment_enabled: ${{ github.event_name == 'pull_request' && 'true' || 'false' }}
github_token: ${{ secrets.GIT_PAT }} # Required when PR comments is enabled
#polaris_reports_sarif_create: ${{ github.event_name != 'pull_request' && 'true' || 'false' }}
polaris_reports_sarif_severities: "CRITICAL,HIGH,MEDIUM,LOW"
polaris_reports_sarif_groupSCAIssues: true
polaris_reports_sarif_create: true
polaris_upload_sarif_report: true
polaris_reports_sarif_issue_types: 'SCA, SAST'
# polaris_upload_sarif_report: ${{ github.event_name != 'pull_request' && 'true' || 'false' }}


#- name: Save Logs
# if: always()
# uses: actions/upload-artifact@v3
# with:
# name: bridge-logs
#path: ${{ github.workspace }}/.bridge/**/*.json

4 changes: 4 additions & 0 deletions .github/workflows/blackduck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,11 @@ jobs:
- uses: actions/setup-java@v1
with:
java-version: 11

- name: Black Duck Scan
uses: blackducksoftware/github-action@v2
with:
args: --detect.project.name=$PROJECT --detect.project.version.name=$BRANCH --detect.excluded.detector.types=GRADLE
- name: Upload to CoPilot
if: github.event_name == 'push' || github.event_name == 'pull_request'
run: bash <(curl -s https://copilot.blackducksoftware.com/ci/githubactions/scripts/upload)
39 changes: 39 additions & 0 deletions .github/workflows/demo.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: CI-Polaris-1
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: Checkout Source
uses: actions/checkout@v4
- name: Setup Java JDK
uses: actions/setup-java@v4
with:
java-version: 11
distribution: microsoft
cache: maven
- name: Polaris Scan
uses: synopsys-sig/[email protected]
with:
### SCANNING: Required fields
polaris_server_url: ${{ vars.POLARIS_SERVERURL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"

### SCANNING: Optional fields
polaris_application_name: AJW-${{ github.event.repository.name }}
# polaris_project_name: ${{ github.event.repository.name }}

### PULL REQUEST COMMENTS: Uncomment below to enable
polaris_prComment_enabled: true
github_token: ${{ secrets.GIT_PAT }} # Required when PR comments is enabled

### SARIF report parameters
polaris_reports_sarif_create: true
polaris_upload_sarif_report: true
37 changes: 37 additions & 0 deletions .github/workflows/demoyml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: CI-Polaris-Jose
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: Checkout Source
uses: actions/checkout@v4
- name: Polaris Scan
uses: synopsys-sig/[email protected]
with:
### SCANNING: Required fields
polaris_server_url: ${{ vars.POLARIS_SERVERURL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"

### SCANNING: Optional fields
# polaris_application_name: ${{ github.event.repository.name }}
# polaris_project_name: ${{ github.event.repository.name }}

### PULL REQUEST COMMENTS: Uncomment below to enable
# polaris_prComment_enabled: true
# github_token: ${{ secrets.GITHUB_TOKEN }} # Required when PR comments is enabled

polaris_reports_sarif_create: true
# polaris_reports_sarif_file_path: '/Users/tmp/report.sarif.json' # File path (including file name) where SARIF report is created.
polaris_reports_sarif_severities: "CRITICAL,HIGH"
polaris_reports_sarif_groupSCAIssues: true
polaris_reports_sarif_issue_types: 'SCA, SAST'
polaris_upload_sarif_report: true
github_token: ${{ secrets.GITHUB_TOKEN }} # Required when polaris_upload_sarif_report is set as true
44 changes: 44 additions & 0 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: CI-Polaris-Basic
on:
push:
branches: [ main, master, develop, stage, release ]
pull_request:
branches: [ main, master, develop, stage, release ]
workflow_dispatch:

jobs:
build:
runs-on: [ ubuntu-latest ]
steps:
- name: Checkout Source
uses: actions/checkout@v4
- name: Setup Java JDK
uses: actions/setup-java@v4
with:
java-version: 17
distribution: microsoft
cache: maven
- name: NEW Polaris Scan 1
uses: synopsys-sig/[email protected]
with:
### SCANNING: Required fields
polaris_server_url: ${{ secrets.POLARIS_SERVER_URL }}
polaris_access_token: ${{ secrets.POLARIS_ACCESS_TOKEN }}
polaris_assessment_types: "SCA,SAST"
polaris_application_name: "JWtest"
polaris_project_name: "HelloJava"
polaris_branch_name: "main"


### PULL REQUEST COMMENTS: Uncomment below to enable
polaris_prComment_enabled: ${{ github.event_name == 'pull_request' && 'true' || 'false' }}
polaris_prComment_enabled: true
github_token: ${{ secrets.git_pat }} # Required when PR comments is enabled

#- name: Save Logs
# if: always()
# uses: actions/upload-artifact@v3
# with:
# name: bridge-logs
#path: ${{ github.workspace }}/.bridge/**/*.json

Loading