Skip to content

Commit

Permalink
Add missing Snyk / SCA / SAST scans to CI
Browse files Browse the repository at this point in the history
  • Loading branch information
ChrisBAshton authored Apr 29, 2024
1 parent 666be0f commit 94cd004
Showing 1 changed file with 19 additions and 0 deletions.
19 changes: 19 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,25 @@ on:
pull_request:

jobs:
snyk-security:
name: SNYK security analysis
uses: alphagov/govuk-infrastructure/.github/workflows/snyk-security.yml@main
secrets: inherit
permissions:
contents: read
security-events: write
actions: read

codeql-sast:
name: CodeQL SAST scan
uses: alphagov/govuk-infrastructure/.github/workflows/codeql-analysis.yml@main
permissions:
security-events: write

dependency-review:
name: Dependency Review scan
uses: alphagov/govuk-infrastructure/.github/workflows/dependency-review.yml@main

test:
name: Test Extension JS
runs-on: ubuntu-latest
Expand Down

0 comments on commit 94cd004

Please sign in to comment.