Skip to content

Dependency Scanning #91

Dependency Scanning

Dependency Scanning #91

Workflow file for this run

name: Dependency Scanning
on:
workflow_dispatch:
schedule:
- cron: '0 0 * * 0' # At 00:00 on Sunday
permissions:
contents: read # allow actions/checkout
jobs:
fossa:
name: Fossa
runs-on: ubuntu-22.04
if: github.event.repository.fork == false
steps:
- name: Checkout
# https://github.com/actions/checkout/releases
# v4.1.1
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
- name: Cache Coursier cache
# https://github.com/coursier/cache-action/releases
# v6.4.3
uses: coursier/cache-action@566e01fea33492e5a89706b43fb0d3fc884154f9
- name: Set up JDK 17
# https://github.com/coursier/setup-action/releases
# v1.3.5
uses: coursier/setup-action@7bde40eee928896f074dbb76d22dd772eed5c65f
with:
jvm: temurin:1.17
- name: FOSSA policy check
run: |-
curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install-latest.sh | bash
sbt "compile; makePom"
echo ### List targets ###
fossa list-targets
echo ### Java SDK (code-first) ###
fossa analyze -p kalix-java-sdk-spring \
--only-target scala@sdk/java-sdk-spring/target/ \
--only-target scala@sdk/java-sdk-spring-testkit/target/ \
--only-target scala@sdk/spring-boot-starter/target/
echo ### Java SDK (protobuf) including Maven codegen ###
fossa analyze -p kalix-java-sdk-protobuf \
--only-target scala@sdk/java-sdk-protobuf/target/ \
--only-target scala@sdk/java-sdk-protobuf-testkit/target/ \
--only-target scala@codegen/java-gen/target/scala-2.12/ \
--only-target maven@maven-java/
echo ### Scala SDK (protobuf) including core and sbt codegen ##
fossa analyze -p kalix-scala-sdk-protobuf \
--only-target scala@sdk/scala-sdk-protobuf/target/scala-2.13/ \
--only-target scala@sdk/scala-sdk-protobuf-testkit/target/scala-2.13/ \
--only-target scala@codegen/scala-gen/target/scala-2.12/ \
--only-target scala@codegen/core/target/scala-2.12/ \
--only-target scala@sbt-plugin/target/scala-2.12/sbt-1.0/
echo ### report all parts including testkits, tests, TCKs, and samples ###
fossa analyze -p kalix-jvm-sdk
env:
FOSSA_API_KEY: "${{secrets.FOSSA_API_KEY}}"
FOSSA_TELEMETRY_SCOPE: off