diff --git a/.github/workflows/synopsys-schedule.yaml b/.github/workflows/synopsys-schedule.yaml index f1c5fdc..f8dec3e 100644 --- a/.github/workflows/synopsys-schedule.yaml +++ b/.github/workflows/synopsys-schedule.yaml @@ -1,4 +1,4 @@ -name: Black Duck Intelligent Policy Check +name: Black Duck Daily Policy Check on: schedule: - cron: "0 0 * * *" @@ -24,11 +24,11 @@ jobs: - name: Build Project run: make build - - name: Run Synopsys Detect - uses: synopsys-sig/detect-action@v0.3.4 + - name: Black Duck Full Scan + uses: synopsys-sig/synopsys-action@v1.7.0 with: - scan-mode: INTELLIGENT - github-token: ${{ secrets.GITHUB_TOKEN }} - detect-version: 8.10.0 - blackduck-url: ${{ secrets.BLACKDUCK_URL }} - blackduck-api-token: ${{ secrets.BLACKDUCK_API_TOKEN }} + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_apiToken: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: true + blackduck_scan_failure_severities: 'BLOCKER,CRITICAL' \ No newline at end of file diff --git a/.github/workflows/synopsys.yaml b/.github/workflows/synopsys.yaml index 2b9ba55..a7f657e 100644 --- a/.github/workflows/synopsys.yaml +++ b/.github/workflows/synopsys.yaml @@ -26,10 +26,24 @@ jobs: - name: Build Project run: make build - - name: Run Synopsys Detect - uses: synopsys-sig/detect-action@v0.3.4 + - name: Black Duck Full Scan + if: ${{ github.event_name != 'pull_request' }} + uses: synopsys-sig/synopsys-action@v1.7.0 with: - github-token: ${{ secrets.GITHUB_TOKEN }} - detect-version: 8.10.0 - blackduck-url: ${{ secrets.BLACKDUCK_URL }} - blackduck-api-token: ${{ secrets.BLACKDUCK_API_TOKEN }} + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_token: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: true + blackduck_scan_failure_severities: 'BLOCKER,CRITICAL' + + - name: Black Duck PR Scan + if: ${{ github.event_name == 'pull_request' }} + uses: synopsys-sig/synopsys-action@v1.7.0 + env: + DETECT_PROJECT_VERSION_NAME: ${{ github.base_ref }} + with: + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_token: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: false + blackduck_prComment_enabled: true \ No newline at end of file