Library updates for cve's, suppression cleanup and not fail github action job SonarCloud if SONARCLOUD_TOKEN not found (summary report instead).#1667
Conversation
|
Merge conflicts |
12cbad7 to
f75e89e
Compare
* Library updates * Dependancy suppression cleanup
|
@lukaszlenart rebased and put back to be spring6 base. Also fixed up owasp testing results (including caching of db). Enabled test results to be surfaced by github actions as well as annotations. |
lukaszlenart
left a comment
There was a problem hiding this comment.
All looks good, let me know if you are going to address this few non-blocking issues? I'm fine to address them later
| push: | ||
| branches: | ||
| - 'main' | ||
| - 'develop' |
There was a problem hiding this comment.
We do not use the "develop" branch, but that's fine
…se use mirror for forks not configured, remove workflow_call for now since we don't on call
|
Updated per your comments, I've allowed NIST_NVD_API_KEY usage as well as non (do note that NIST make take a very long time to load cache so lets see how we go on this utilisation, I've seen up to 6hours to re-create the cache db) |
Library updates:
Dependancy suppression cleanup
Sonar github workflow to be skipped if secret is not found
Struts & Spring Compatibility Matrix