audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit bb5178c69d

bb5178c69d0d07fb0c9a5221d50e169882009426

parent: f1bee242e1

Unsigned

Christian Cleberg <156287552+ccleberg@users.noreply.github.com> 路 2024-11-07 01:37 UTC
committer: <noreply@github.com>

Create crda.yml

Layout: unified 路 split

.github/workflows/crda.yml added +130
@@ -0,0 +1,130 @@
1# This workflow uses actions that are not certified by GitHub.
2# They are provided by a third-party and are governed by
3# separate terms of service, privacy policy, and support
4# documentation.
5
6# This workflow performs a static analysis of your source code using
7# Red Hat CodeReady Dependency Analytics.
8
9# Scans are triggered:
10# 1. On every push to default and protected branches
11# 2. On every Pull Request targeting the default branch
12# 3. On a weekly schedule
13# 4. Manually, on demand, via the "workflow_dispatch" event
14
15# 馃拋 The CRDA Starter workflow will:
16# - Checkout your repository
17# - Setup the required tool stack
18# - Install the CRDA command line tool
19# - Auto detect the manifest file and install the project's dependencies
20# - Perform the security scan using CRDA
21# - Upload the SARIF result to the GitHub Code Scanning which can be viewed under the security tab
22# - Optionally upload the SARIF file as an artifact for the future reference
23
24# 鈩癸笍 Configure your repository and the workflow with the following steps:
25# 1. Setup the tool stack based on the project's requirement.
26# Refer to: https://github.com/redhat-actions/crda/#1-set-up-the-tool-stack
27# 2. (Optional) CRDA action attempt to detect the language and install the
28# required dependencies for your project. If your project doesn't aligns
29# with the default dependency installation command mentioned here
30# https://github.com/redhat-actions/crda/#3-installing-dependencies.
31# Use the required inputs to setup the same
32# 3. (Optional) CRDA action attempts to detect the manifest file if it is
33# present in the root of the project and named as per the default mentioned
34# here https://github.com/redhat-actions/crda/#3-installing-dependencies.
35# If it deviates from the default, use the required inputs to setup the same
36# 4. Setup Authentication - Create the CRDA_KEY or SNYK_TOKEN.
37# Refer to: https://github.com/redhat-actions/crda/#4-set-up-authentication
38# 5. (Optional) Upload SARIF file as an Artifact to download and view
39# 6. Commit and push the workflow file to your default branch to trigger a workflow run.
40
41# 馃憢 Visit our GitHub organization at https://github.com/redhat-actions/ to see our actions and provide feedback.
42
43name: CRDA Scan
44
45# Controls when the workflow will run
46on:
47 # TODO: Customize trigger events based on your DevSecOps processes
48 #
49 # This workflow is made to run with OpenShift starter workflow
50 # https://github.com/actions/starter-workflows/blob/main/deployments/openshift.yml
51 # However, if you want to run this workflow as a standalone workflow, please
52 # uncomment the 'push' trigger below and configure it based on your requirements.
53 #
54 workflow_call:
55 secrets:
56 CRDA_KEY:
57 required: false
58 SNYK_TOKEN:
59 required: false
60 workflow_dispatch:
61
62 push:
63 branches: [ "main" ]
64
65 # pull_request_target is used to securely share secret to the PR's workflow run.
66 # For more info visit: https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target
67 pull_request_target:
68 branches: [ "main" ]
69 types: [ assigned, opened, synchronize, reopened, labeled, edited ]
70
71permissions:
72 contents: read
73
74jobs:
75 crda-scan:
76 permissions:
77 contents: read # for actions/checkout to fetch code
78 security-events: write # for redhat-actions/crda to upload SARIF results
79 name: Scan project vulnerabilities with CRDA
80 runs-on: ubuntu-20.04
81 steps:
82
83 - name: Check out repository
84 uses: actions/checkout@v4
85
86 # *******************************************************************
87 # Required: Instructions to setup project
88 # 1. Setup Go, Java, Node.js or Python depending on your project type
89 # 2. Setup Actions are listed below, choose one from them:
90 # - Go: https://github.com/actions/setup-go
91 # - Java: https://github.com/actions/setup-java
92 # - Node.js: https://github.com/actions/setup-node
93 # - Python: https://github.com/actions/setup-python
94 #
95 # Example:
96 # - name: Setup Node
97 # uses: actions/setup-node@v4
98 # with:
99 # node-version: '20'
100 - name: Setup Python
101 uses: actions/setup-python@v5
102 with:
103 python-version: '3.13'
104
105 # https://github.com/redhat-actions/openshift-tools-installer/blob/main/README.md
106 - name: Install CRDA CLI
107 uses: redhat-actions/openshift-tools-installer@v1
108 with:
109 source: github
110 github_pat: ${{ github.token }}
111 # Choose the desired version of the CRDA CLI
112 crda: "latest"
113
114 ######################################################################################
115 # https://github.com/redhat-actions/crda/blob/main/README.md
116 #
117 # By default, CRDA will detect the manifest file and install the required dependencies
118 # using the standard command for the project type.
119 # If your project doesn't aligns with the defaults mentioned in this action, you will
120 # need to set few inputs that are described here:
121 # https://github.com/redhat-actions/crda/blob/main/README.md#3-installing-dependencies
122 # Visit https://github.com/redhat-actions/crda/#4-set-up-authentication to understand
123 # process to get a SNYK_TOKEN or a CRDA_KEY
124 - name: CRDA Scan
125 id: scan
126 uses: redhat-actions/crda@v1
127 with:
128 crda_key: ${{ secrets.CRDA_KEY }} # Either use crda_key or snyk_token
129 # snyk_token: ${{ secrets.SNYK_TOKEN }}
130 # upload_artifact: false # Set this to false to skip artifact upload