Skip to content

chore(deps): bump org.springframework.boot from 3.2.2 to 3.3.0 #20

chore(deps): bump org.springframework.boot from 3.2.2 to 3.3.0

chore(deps): bump org.springframework.boot from 3.2.2 to 3.3.0 #20

Workflow file for this run

name: CI
on:
pull_request:
permissions:
contents: read
actions: read
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-java@v4
with:
distribution: adopt
java-version: 21
check-latest: true
- run: ( ./gradlew clean build )
unit-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-java@v4
with:
distribution: adopt
java-version: 21
check-latest: true
name: "Executing unit tests and checking code coverage"
- run: ( ./gradlew pitest )
name: "Executing mutation tests"
- run: ( ./gradlew dependencyCheckAnalyze )
name: "Executing dependency vulnerability checks"
trivy-static-analysis:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Trivy Static Security Analysis
run: |
echo "**********************************************************************************************"
echo "**********************************************************************************************"
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
-v $HOME/Library/Caches:/root/.cache/ \
-v ./:/scan -w /scan aquasec/trivy:0.50.1 \
config --severity "HIGH,CRITICAL" -f sarif -o results.sarif --exit-code 1 --misconfig-scanners=dockerfile /scan/Dockerfile
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
# Path to SARIF file relative to the root of the repository
sarif_file: results.sarif
# Optional category for the results
# Used to differentiate multiple results for one commit
category: trivy-analysis