feat: Added localization for timeaxis #18
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: CI Security Pipeline | |
on: | |
push: | |
branches: [develop] | |
pull_request: | |
branches: [develop] | |
jobs: | |
security-checks: | |
name: Security Checks | |
runs-on: ubuntu-latest | |
strategy: | |
matrix: | |
node-version: [20.x, 22.x] | |
fail-fast: false | |
permissions: | |
contents: read | |
security-events: write | |
steps: | |
- name: Checkout Repository | |
uses: actions/checkout@v4 | |
- name: Setup Node.js ${{ matrix.node-version }} | |
uses: actions/[email protected] | |
with: | |
node-version: ${{ matrix.node-version }} | |
cache: "npm" | |
- name: Install Dependencies | |
run: | | |
npm cache clean --force | |
npm ci | |
- name: Build | |
run: npm run build | |
- name: Run Tests | |
run: npm run test | |
- name: OWASP Dependency Check | |
id: dependency-check | |
continue-on-error: true | |
uses: dependency-check/Dependency-Check_Action@main | |
with: | |
project: "HyVueGantt" | |
path: "." | |
format: "HTML" | |
args: > | |
--failOnCVSS 7 | |
--enableRetired | |
- name: Run Syft | |
uses: anchore/[email protected] | |
with: | |
format: spdx-json | |
file: package-lock.json | |
artifact-name: sbom-${{ github.event.repository.name }}-${{ matrix.node-version }}.spdx.json | |
output-file: sbom-${{ github.event.repository.name }}-${{ matrix.node-version }}.spdx.json | |
- name: Run Grype | |
uses: anchore/[email protected] | |
continue-on-error: true | |
with: | |
sbom: sbom-${{ github.event.repository.name }}-${{ matrix.node-version }}.spdx.json | |
fail-build: true | |
severity-cutoff: "high" | |
output-format: json | |
output-file: grype-results.json | |
- name: Archive Security Results | |
uses: actions/[email protected] | |
if: always() | |
with: | |
name: security-scan-results-node-${{ matrix.node-version }} | |
path: | | |
dependency-check-report.html | |
sbom-${{ github.event.repository.name }}-${{ matrix.node-version }}.spdx.json | |
${{github.workspace}}/reports | |
grype-results.json | |
retention-days: 2 | |
#- name: Notify on Failure | |
# if: failure() | |
# uses: actions/github-script@v7 | |
# with: | |
# script: | | |
# const nodeVersion = '${{ matrix.node }}'; | |
# github.rest.issues.create({ | |
# owner: context.repo.owner, | |
# repo: context.repo.repo, | |
# title: `Security Scan Failed - Node ${nodeVersion}`, | |
# body: `Security scan failed for Node.js ${nodeVersion} in workflow run: ${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`, | |
# labels: ['security', 'ci-failure'] | |
# }) |