[Snyk] Security upgrade @aws-sdk/client-s3 from 3.583.0 to 3.621.0 #57
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# This workflow will do a clean installation of node dependencies, cache/restore them, build the source code and run tests | |
# For more information see: https://help.github.com/actions/language-and-framework-guides/using-nodejs-with-github-actions | |
name: PR-checks | |
on: | |
push: | |
branches: ['develop'] | |
pull_request: | |
branches: ['develop'] | |
jobs: | |
build-test: | |
runs-on: ubuntu-latest | |
timeout-minutes: 15 | |
strategy: | |
fail-fast: false | |
matrix: | |
node-version: [18.x] | |
# See supported Node.js release schedule at https://nodejs.org/en/about/releases/ | |
steps: | |
- uses: actions/checkout@v3 | |
- name: Setup Node.js ${{ matrix.node-version }} | |
uses: actions/setup-node@v3 | |
with: | |
node-version: ${{ matrix.node-version }} | |
cache: 'npm' | |
- name: Install dependencies | |
run: npm ci | |
- name: Unit tests | |
run: npm run test | |
- name: Build | |
run: npm run build | |
- name: Integration tests | |
run: npm run test-i | |
scanner: | |
permissions: | |
id-token: write | |
runs-on: X64 | |
steps: | |
- uses: actions/checkout@v4 | |
- uses: actions/setup-node@v4 | |
with: | |
node-version-file: '.nvmrc' | |
- uses: aws-actions/configure-aws-credentials@v4 | |
with: | |
role-to-assume: ${{ secrets.CVS_MGMT_AWS_ROLE }} | |
aws-region: ${{ secrets.DVSA_AWS_REGION }} | |
role-session-name: 'cvs-app-vtm' | |
- uses: aws-actions/aws-secretsmanager-get-secrets@v1 | |
with: | |
secret-ids: sonarqube-gha | |
parse-json-secrets: true | |
- name: Install dependencies | |
run: npm ci | |
- name: Run SonarQube scanner | |
run: | | |
npm run test:unit:coverage && \ | |
npm run sonar-scanner -- \ | |
-Dsonar.host.url=${{ env.SONARQUBE_GHA_URL }} \ | |
-Dsonar.token=${{ env.SONARQUBE_GHA_TOKEN }} \ | |
-Dsonar.login=${{ env.SONARQUBE_GHA_TOKEN }} \ | |
-Dsonar.projectName=${{ github.repository }} \ | |
-Dsonar.projectVersion=1.0.${{ github.run_id }} |