File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -10,8 +10,7 @@ private admin repo.
1010
1111- ` GPG_PASSWORD ` - stored in OpenTelemetry-Java 1Password
1212- ` GPG_PRIVATE_KEY ` - stored in OpenTelemetry-Java 1Password
13- - ` SONATYPE_OSS_INDEX_USER ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
14- - ` SONATYPE_OSS_INDEX_PASSWORD ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
13+ - ` SONATYPE_GUIDE_PAT ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1514- ` SONATYPE_KEY ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1615- ` SONATYPE_USER ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1716
Original file line number Diff line number Diff line change 11# the benefit of this over renovate is that this also analyzes transitive dependencies
22# while renovate (at least currently) only analyzes top-level dependencies
3- name : OSS Index dependency audit (daily)
3+ name : Sonatype Guide dependency audit (daily)
44
55on :
66 schedule :
@@ -29,14 +29,13 @@ jobs:
2929 id : audit
3030 continue-on-error : true
3131 env :
32- SONATYPE_OSS_INDEX_USER : ${{ secrets.SONATYPE_OSS_INDEX_USER }}
33- SONATYPE_OSS_INDEX_PASSWORD : ${{ secrets.SONATYPE_OSS_INDEX_PASSWORD }}
32+ SONATYPE_GUIDE_PAT : ${{ secrets.SONATYPE_GUIDE_PAT }}
3433 DEVELOCITY_ACCESS_KEY : ${{ secrets.DEVELOCITY_ACCESS_KEY }}
3534
3635 - name : Print vulnerability report
3736 if : steps.audit.outcome == 'failure'
3837 run : |
39- echo "=== OSS Index Vulnerability Report ==="
38+ echo "=== Sonatype Guide Vulnerability Report ==="
4039 find . -name "oss-index-cyclonedx-bom.json" | xargs cat
4140 exit 1
4241
Original file line number Diff line number Diff line change @@ -49,8 +49,9 @@ checkstyle {
4949}
5050
5151ossIndexAudit {
52- username = System .getenv(" SONATYPE_OSS_INDEX_USER" ) ? : " "
53- password = System .getenv(" SONATYPE_OSS_INDEX_PASSWORD" ) ? : " "
52+ // Guide PAT authentication ignores this, but the scan plugin requires it.
53+ username = " unused"
54+ password = System .getenv(" SONATYPE_GUIDE_PAT" ) ? : " "
5455 outputFormat = org.sonatype.gradle.plugins.scan.ossindex.OutputFormat .JSON_CYCLONE_DX_1_4
5556 isPrintBanner = false
5657}
You can’t perform that action at this time.
0 commit comments