ci: add snyk scans #3

merged
opened by quietengineer.fyi targeting main from workflows
Changed files
+28
.tangled
workflows
+28
.tangled/workflows/security.yaml
···
+
when:
+
- event: ["push", "pull_request"]
+
branch: ["main", "develop"]
+
- event: ["manual"]
+
+
engine: "nixery"
+
+
dependencies:
+
nixpkgs:
+
- go
+
- snyk
+
+
environment:
+
SNYK_DISABLE_ANALYTICS: 1
+
+
steps:
+
- name: build application
+
command: |
+
go build -v ./...
+
+
- name: snyk auth
+
command: |
+
snyk auth "$SNYK_TOKEN"
+
+
- name: snyk test
+
command: |
+
snyk monitor --all-projects
+
snyk test --all-projects