Repository navigation
Bump virtualenv from 21.7.4 to 21.7.9 #53
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Socket Basics Security Scan | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, reopened] | |
| jobs: | |
| socket-basics-security-scan: | |
| # We intentionally run this shared action from @main, not from a pinned sha | |
| # this is because we control the ynab-sast-scanner repo, so there is not a significant risk of malicious changes being pushed. | |
| # Plus, the shared action does use pinned dependencies, and so will be updated fairly often. When we do that, we do not | |
| # want to have to update the sha in every repo that uses this shared action, before such updates apply. | |
| uses: ynab/ynab-sast-scanner/.github/workflows/socket-basics.yml@main | |
| secrets: | |
| SOCKET_SECURITY_API_KEY: ${{ secrets.SOCKET_SECURITY_API_KEY }} | |
| SAST_SUPPRESSIONS_APP_PRIVATE_KEY: ${{ secrets.SAST_SUPPRESSIONS_APP_PRIVATE_KEY }} |