Skip to content

Commit 78947ac

Browse files
security: use datadog-ci CLI installer and pin version
1 parent a5ac864 commit 78947ac

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

.github/workflows/analyze-changes.yaml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -107,11 +107,12 @@ jobs:
107107
with:
108108
sarif_file: 'trivy-results.sarif'
109109

110+
- name: Install datadog-ci
111+
uses: DataDog/install-datadog-ci-github-action@6d7f0c7c5402a4b1912055b76970ca76bef71fe5 # v1.0.4
112+
with:
113+
version: v5.16.1
110114
- name: Upload results to Datadog CI Static Analysis
111-
run: |
112-
wget --no-verbose https://github.com/DataDog/datadog-ci/releases/latest/download/datadog-ci_linux-x64 -O datadog-ci
113-
chmod +x datadog-ci
114-
./datadog-ci sarif upload trivy-results.sarif --service dd-trace-java --env ci
115+
run: datadog-ci sarif upload trivy-results.sarif --service dd-trace-java --env ci
115116
env:
116117
DD_API_KEY: ${{ secrets.DATADOG_API_KEY_PROD }}
117118
DD_SITE: datadoghq.com

0 commit comments

Comments
 (0)