Skip to content

Bump virtualenv from 21.7.4 to 21.7.9 #53

Bump virtualenv from 21.7.4 to 21.7.9

Bump virtualenv from 21.7.4 to 21.7.9 #53

Workflow file for this run

name: Socket Basics Security Scan
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
socket-basics-security-scan:
# We intentionally run this shared action from @main, not from a pinned sha
# this is because we control the ynab-sast-scanner repo, so there is not a significant risk of malicious changes being pushed.
# Plus, the shared action does use pinned dependencies, and so will be updated fairly often. When we do that, we do not
# want to have to update the sha in every repo that uses this shared action, before such updates apply.
uses: ynab/ynab-sast-scanner/.github/workflows/socket-basics.yml@main
secrets:
SOCKET_SECURITY_API_KEY: ${{ secrets.SOCKET_SECURITY_API_KEY }}
SAST_SUPPRESSIONS_APP_PRIVATE_KEY: ${{ secrets.SAST_SUPPRESSIONS_APP_PRIVATE_KEY }}