Skip to content

Bump sonarsource/sonarqube-scan-action from 2.0.2 to 2.1.0 #125

Bump sonarsource/sonarqube-scan-action from 2.0.2 to 2.1.0

Bump sonarsource/sonarqube-scan-action from 2.0.2 to 2.1.0 #125

Workflow file for this run

# SPDX-FileCopyrightText: 2022 Winni Neessen <[email protected]>
#
# SPDX-License-Identifier: CC0-1.0
name: Govulncheck Security Scan
on: [push, pull_request]
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@f086349bfa2bd1361f7909c78558e816508cdc10 # v2.8.0
with:
egress-policy: audit
- name: Run govulncheck
uses: golang/govulncheck-action@3a32958c2706f7048305d5a2e53633d7e37e97d0 # v1.0.2