.github/workflows/ci.yml in rack-logstasher-2.0.0 vs .github/workflows/ci.yml in rack-logstasher-2.1.0
- old
+ new
@@ -1,16 +1,37 @@
on: [push, pull_request]
jobs:
+ snyk-security:
+ name: SNYK security analysis
+ uses: alphagov/govuk-infrastructure/.github/workflows/snyk-security.yml@main
+ with:
+ skip_sca: true
+ secrets: inherit
+ permissions:
+ contents: read
+ security-events: write
+ actions: read
+
+ codeql-sast:
+ name: CodeQL SAST scan
+ uses: alphagov/govuk-infrastructure/.github/workflows/codeql-analysis.yml@main
+ permissions:
+ security-events: write
+
+ dependency-review:
+ name: Dependency Review scan
+ uses: alphagov/govuk-infrastructure/.github/workflows/dependency-review.yml@main
+
test_matrix:
strategy:
fail-fast: false
matrix:
# Due to https://github.com/actions/runner/issues/849, we have to use quotes for '3.0'
- ruby: [2.7, '3.0', 3.1, 3.2]
+ ruby: ['3.0', 3.1, 3.2]
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v3
+ - uses: actions/checkout@v4
- uses: ruby/setup-ruby@v1
with:
ruby-version: ${{ matrix.ruby }}
bundler-cache: true
- run: bundle exec rake