From 2fb0e30e13ee7fc2a1e0032a7849dcc827e600ba Mon Sep 17 00:00:00 2001 From: "Chayim I. Kirshen" Date: Thu, 11 Aug 2022 09:14:26 +0300 Subject: [PATCH 1/2] Adding dependency auditing to CI --- .github/workflows/integration.yaml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/integration.yaml b/.github/workflows/integration.yaml index 5876c08738..cce9a1f835 100644 --- a/.github/workflows/integration.yaml +++ b/.github/workflows/integration.yaml @@ -18,6 +18,15 @@ on: jobs: + dependency-audit: + name: Dependency audit + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + - uses: trailofbits/gh-action-pip-audit@v1.0.0 + with: + inputs: requirements.txt dev)requirements.txt + lint: name: Code linters runs-on: ubuntu-latest From a860a6eb4b43ba8932682309bdf2de69849da5c0 Mon Sep 17 00:00:00 2001 From: "Chayim I. Kirshen" Date: Thu, 11 Aug 2022 10:11:04 +0300 Subject: [PATCH 2/2] fixing pathing --- .github/workflows/integration.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/integration.yaml b/.github/workflows/integration.yaml index cce9a1f835..56dc286bc3 100644 --- a/.github/workflows/integration.yaml +++ b/.github/workflows/integration.yaml @@ -25,7 +25,7 @@ jobs: - uses: actions/checkout@v3 - uses: trailofbits/gh-action-pip-audit@v1.0.0 with: - inputs: requirements.txt dev)requirements.txt + inputs: requirements.txt dev_requirements.txt lint: name: Code linters