Skip to content

fix(deps): update azure sdk dependencies {patch} (minor) - autoclosed #87

fix(deps): update azure sdk dependencies {patch} (minor) - autoclosed

fix(deps): update azure sdk dependencies {patch} (minor) - autoclosed #87

name: "DependencyCheck"
on:
push:
branches: ["main"]
pull_request:
# The branches below must be a subset of the branches above
branches: ["main"]
paths:
- "gradle/**"
- "config/dependency-check/**"
- ".release-trigger"
workflow_dispatch:
schedule:
# * is a special character in YAML, so we have to quote this string
- cron: "0 7 * * 2,4,6"
permissions: read-all
jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: Validate Gradle wrapper
uses: gradle/actions/wrapper-validation@50e97c2cd7a37755bbfafc9c5b7cafaece252f6e # v6.1.0
- name: Set up JDK 25
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5.2.0
with:
distribution: temurin
java-version: 25
- name: Setup Gradle
uses: gradle/actions/setup-gradle@50e97c2cd7a37755bbfafc9c5b7cafaece252f6e # v6.1.0
- name: Cache DependencyCheck data
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ${{ env.GRADLE_USER_HOME }}/dependency-check-data/**
key: gradle-build-dependency-check
restore-keys: |
gradle-build-dependency-check
- name: Check dependencies with Gradle
run: >
./gradlew dependencyCheckAnalyze
-PnvdApiKey=${{ secrets.NVD_API_KEY }}
-PossIndexUsername=${{ secrets.OSS_INDEX_USER }}
-PossIndexPassword=${{ secrets.OSS_INDEX_PASSWORD }}
--no-parallel