diff --git a/.github/workflows/synopsys-schedule.yaml b/.github/workflows/synopsys-schedule.yaml index f8e030c719..a6957053f9 100644 --- a/.github/workflows/synopsys-schedule.yaml +++ b/.github/workflows/synopsys-schedule.yaml @@ -1,4 +1,4 @@ -name: Black Duck Intelligent Policy Check +name: Black Duck Daily Policy Check on: schedule: - cron: "0 0 * * *" @@ -20,11 +20,11 @@ jobs: - name: Build Project run: devbox run -- make build - - name: Run Synopsys Detect - uses: synopsys-sig/detect-action@v0.3.4 + - name: Black Duck Full Scan + uses: synopsys-sig/synopsys-action@v1.7.0 with: - scan-mode: INTELLIGENT - github-token: ${{ secrets.GITHUB_TOKEN }} - detect-version: 8.10.0 - blackduck-url: ${{ secrets.BLACKDUCK_URL }} - blackduck-api-token: ${{ secrets.BLACKDUCK_API_TOKEN }} + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_apiToken: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: true + blackduck_scan_failure_severities: 'BLOCKER,CRITICAL' diff --git a/.github/workflows/synopsys.yaml b/.github/workflows/synopsys.yaml index cfe9a1a6c9..3486622235 100644 --- a/.github/workflows/synopsys.yaml +++ b/.github/workflows/synopsys.yaml @@ -21,10 +21,24 @@ jobs: - name: Build Project run: devbox run -- make build - - name: Run Synopsys Detect - uses: synopsys-sig/detect-action@v0.3.4 + - name: Black Duck Full Scan + if: ${{ github.event_name != 'pull_request' }} + uses: synopsys-sig/synopsys-action@v1.7.0 with: - github-token: ${{ secrets.GITHUB_TOKEN }} - detect-version: 8.10.0 - blackduck-url: ${{ secrets.BLACKDUCK_URL }} - blackduck-api-token: ${{ secrets.BLACKDUCK_API_TOKEN }} + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_token: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: true + blackduck_scan_failure_severities: 'BLOCKER,CRITICAL' + + - name: Black Duck PR Scan + if: ${{ github.event_name == 'pull_request' }} + uses: synopsys-sig/synopsys-action@v1.7.0 + env: + DETECT_PROJECT_VERSION_NAME: ${{ github.base_ref }} + with: + blackduck_url: ${{ secrets.BLACKDUCK_URL }} + blackduck_token: ${{ secrets.BLACKDUCK_API_TOKEN }} + github_token: ${{ secrets.GITHUB_TOKEN }} + blackduck_scan_full: false + blackduck_prComment_enabled: true