File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -10,8 +10,7 @@ private admin repo.
1010
1111- ` GPG_PASSWORD ` - stored in OpenTelemetry-Java 1Password
1212- ` GPG_PRIVATE_KEY ` - stored in OpenTelemetry-Java 1Password
13- - ` SONATYPE_OSS_INDEX_USER ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
14- - ` SONATYPE_OSS_INDEX_PASSWORD ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
13+ - ` SONATYPE_GUIDE_PAT ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1514- ` SONATYPE_KEY ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1615- ` SONATYPE_USER ` - owned by [ @jack-berg ] ( https://github.com/jack-berg )
1716
Original file line number Diff line number Diff line change 2929 id : audit
3030 continue-on-error : true
3131 env :
32- SONATYPE_OSS_INDEX_USER : ${{ secrets.SONATYPE_OSS_INDEX_USER }}
33- SONATYPE_OSS_INDEX_PASSWORD : ${{ secrets.SONATYPE_OSS_INDEX_PASSWORD }}
32+ SONATYPE_GUIDE_PAT : ${{ secrets.SONATYPE_GUIDE_PAT }}
3433 DEVELOCITY_ACCESS_KEY : ${{ secrets.DEVELOCITY_ACCESS_KEY }}
3534
3635 - name : Print vulnerability report
Original file line number Diff line number Diff line change @@ -49,8 +49,9 @@ checkstyle {
4949}
5050
5151ossIndexAudit {
52- username = System .getenv(" SONATYPE_OSS_INDEX_USER" ) ? : " "
53- password = System .getenv(" SONATYPE_OSS_INDEX_PASSWORD" ) ? : " "
52+ // Guide PAT authentication ignores this, but the scan plugin requires it.
53+ username = " unused"
54+ password = System .getenv(" SONATYPE_GUIDE_PAT" ) ? : " "
5455 outputFormat = org.sonatype.gradle.plugins.scan.ossindex.OutputFormat .JSON_CYCLONE_DX_1_4
5556 isPrintBanner = false
5657}
You can’t perform that action at this time.
0 commit comments