Skip to content

Bump ch.qos.logback:logback-core from 1.4.4 to 1.4.12 #390

Bump ch.qos.logback:logback-core from 1.4.4 to 1.4.12

Bump ch.qos.logback:logback-core from 1.4.4 to 1.4.12 #390

Workflow file for this run

name: CVE Scanning for Maven
on:
workflow_dispatch:
push:
paths:
- 'pom.xml'
- 'allow-list.xml'
- '.github/workflows/cve-scanning.yml'
pull_request:
paths:
- 'pom.xml'
- 'allow-list.xml'
- '.github/workflows/cve-scanning.yml'
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up JDK 11
uses: actions/setup-java@v3
with:
java-version: '11'
distribution: 'temurin'
cache: maven
- name: Build with Maven
run: mvn clean install -DskipTests
- name: CVE scanning
run: mvn org.owasp:dependency-check-maven:check -DfailBuildOnCVSS=7 -DsuppressionFile="allow-list.xml"