Skip to content
This repository was archived by the owner on Apr 12, 2024. It is now read-only.

Commit 2578dcd

Browse files
authored
🧹 Switch to snyk.io (#23)
* Switch to snyk.io * Update deps
1 parent cafaf8e commit 2578dcd

File tree

3 files changed

+16
-19
lines changed

3 files changed

+16
-19
lines changed

.github/workflows/security.yml

Lines changed: 11 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -8,24 +8,23 @@ on:
88
types: [opened, synchronize, reopened]
99

1010
jobs:
11-
build:
12-
name: Trivy code scanning
11+
scan:
12+
name: Snyk code scanning
1313
runs-on: ubuntu-18.04
1414
steps:
1515
- name: Checkout code
1616
uses: actions/checkout@v2
1717

18-
- name: Run Trivy vulnerability scanner in repo mode
19-
uses: aquasecurity/trivy-action@master
18+
- name: Run Snyk to check for vulnerabilities
19+
uses: snyk/actions/golang@master
20+
# To make sure that SARIF upload gets called
21+
continue-on-error: true
22+
env:
23+
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
2024
with:
21-
scan-type: 'fs'
22-
ignore-unfixed: true
23-
format: 'template'
24-
template: '@/contrib/sarif.tpl'
25-
output: 'trivy-results.sarif'
26-
severity: 'CRITICAL,HIGH'
25+
args: --sarif-file-output=snyk.sarif
2726

28-
- name: Upload Trivy scan results to GitHub Security tab
27+
- name: Upload result to GitHub Code Scanning
2928
uses: github/codeql-action/upload-sarif@v1
3029
with:
31-
sarif_file: 'trivy-results.sarif'
30+
sarif_file: snyk.sarif

go.mod

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,6 @@ require (
66
github.com/BurntSushi/toml v0.4.1 // indirect
77
github.com/Microsoft/go-winio v0.5.1 // indirect
88
github.com/blang/semver/v4 v4.0.0
9-
// Fix for GHSA-c2h3-6mxw-7mvq
109
github.com/containerd/containerd v1.5.7 // indirect
1110
github.com/containerd/stargz-snapshotter/estargz v0.9.0 // indirect
1211
github.com/docker/cli v20.10.10+incompatible // indirect
@@ -30,11 +29,7 @@ require (
3029
google.golang.org/genproto v0.0.0-20211027162914-98a5263abeca // indirect
3130
google.golang.org/grpc v1.41.0 // indirect
3231
gotest.tools/v3 v3.0.3
32+
k8s.io/apimachinery v0.22.3 // indirect
3333
k8s.io/klog/v2 v2.30.0 // indirect
3434
sigs.k8s.io/yaml v1.3.0 // indirect
3535
)
36-
37-
exclude (
38-
github.com/dgrijalva/jwt-go v0.0.0-20170104182250-a601269ab70c
39-
github.com/dgrijalva/jwt-go v3.2.0+incompatible
40-
)

go.sum

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -261,6 +261,8 @@ github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSs
261261
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
262262
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
263263
github.com/denverdino/aliyungo v0.0.0-20190125010748-a747050bb1ba/go.mod h1:dV8lFg6daOBZbT6/BDGIz6Y3WFGn8juu6G+CQ6LHtl0=
264+
github.com/dgrijalva/jwt-go v0.0.0-20170104182250-a601269ab70c/go.mod h1:E3ru+11k8xSBh+hMPgOLZmtrrCbhqsmaPHjLKYnJCaQ=
265+
github.com/dgrijalva/jwt-go v3.2.0+incompatible/go.mod h1:E3ru+11k8xSBh+hMPgOLZmtrrCbhqsmaPHjLKYnJCaQ=
264266
github.com/dgryski/go-sip13 v0.0.0-20181026042036-e10d5fee7954/go.mod h1:vAd38F8PWV+bWy6jNmig1y/TA+kYO4g3RSRF0IAv0no=
265267
github.com/dnaeon/go-vcr v1.0.1/go.mod h1:aBB1+wY4s93YsC3HHjMBMrwTj2R9FHDzUr9KyGc8n1E=
266268
github.com/docker/cli v20.10.7+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
@@ -1358,8 +1360,9 @@ k8s.io/apimachinery v0.20.1/go.mod h1:WlLqWAHZGg07AeltaI0MV5uk1Omp8xaN0JGLY6gkRp
13581360
k8s.io/apimachinery v0.20.2/go.mod h1:WlLqWAHZGg07AeltaI0MV5uk1Omp8xaN0JGLY6gkRpU=
13591361
k8s.io/apimachinery v0.20.4/go.mod h1:WlLqWAHZGg07AeltaI0MV5uk1Omp8xaN0JGLY6gkRpU=
13601362
k8s.io/apimachinery v0.20.6/go.mod h1:ejZXtW1Ra6V1O5H8xPBGz+T3+4gfkTCeExAHKU57MAc=
1361-
k8s.io/apimachinery v0.22.2 h1:ejz6y/zNma8clPVfNDLnPbleBo6MpoFy/HBiBqCouVk=
13621363
k8s.io/apimachinery v0.22.2/go.mod h1:O3oNtNadZdeOMxHFVxOreoznohCpy0z6mocxbZr7oJ0=
1364+
k8s.io/apimachinery v0.22.3 h1:mrvBG5CZnEfwgpVqWcrRKvdsYECTrhAR6cApAgdsflk=
1365+
k8s.io/apimachinery v0.22.3/go.mod h1:O3oNtNadZdeOMxHFVxOreoznohCpy0z6mocxbZr7oJ0=
13631366
k8s.io/apiserver v0.20.1/go.mod h1:ro5QHeQkgMS7ZGpvf4tSMx6bBOgPfE+f52KwvXfScaU=
13641367
k8s.io/apiserver v0.20.4/go.mod h1:Mc80thBKOyy7tbvFtB4kJv1kbdD0eIH8k8vianJcbFM=
13651368
k8s.io/apiserver v0.20.6/go.mod h1:QIJXNt6i6JB+0YQRNcS0hdRHJlMhflFmsBDeSgT1r8Q=

0 commit comments

Comments
 (0)