Merge branch 'safety-only-with-api-key' into 'master'
Safety only with API key See merge request fdroid/fdroidserver!1514
This commit is contained in:
commit
72a0ad81b8
@ -262,18 +262,21 @@ lint_format_bandit_checks:
|
|||||||
# so important to scan that kind of install in CI.
|
# so important to scan that kind of install in CI.
|
||||||
# https://docs.safetycli.com/safety-docs/installation/gitlab
|
# https://docs.safetycli.com/safety-docs/installation/gitlab
|
||||||
safety:
|
safety:
|
||||||
only:
|
|
||||||
changes:
|
|
||||||
- .gitlab-ci.yml
|
|
||||||
- .safety-policy.yml
|
|
||||||
- pyproject.toml
|
|
||||||
- setup.py
|
|
||||||
image: debian:bookworm-slim
|
image: debian:bookworm-slim
|
||||||
|
rules:
|
||||||
|
# once only:/changes: are ported to rules:, this could be removed:
|
||||||
|
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
|
||||||
|
when: never
|
||||||
|
- if: $CI_PIPELINE_SOURCE == "push" && $SAFETY_API_KEY
|
||||||
|
changes:
|
||||||
|
- .gitlab-ci.yml
|
||||||
|
- .safety-policy.yml
|
||||||
|
- pyproject.toml
|
||||||
|
- setup.py
|
||||||
<<: *apt-template
|
<<: *apt-template
|
||||||
variables:
|
variables:
|
||||||
LANG: C.UTF-8
|
LANG: C.UTF-8
|
||||||
script:
|
script:
|
||||||
- test -n "$SAFETY_API_KEY" || exit 0
|
|
||||||
- apt-get install
|
- apt-get install
|
||||||
fdroidserver
|
fdroidserver
|
||||||
python3-biplist
|
python3-biplist
|
||||||
|
@ -39,7 +39,7 @@ report:
|
|||||||
reason: We get these packages from Debian, zipp is not used in production, and its only a DoS.
|
reason: We get these packages from Debian, zipp is not used in production, and its only a DoS.
|
||||||
expires: '2026-08-31'
|
expires: '2026-08-31'
|
||||||
72236:
|
72236:
|
||||||
reason: setuptools comes from Debian
|
reason: setuptools is not used in production to download or install packages, they come from Debian.
|
||||||
expires: '2026-08-31'
|
expires: '2026-08-31'
|
||||||
|
|
||||||
fail-scan-with-exit-code:
|
fail-scan-with-exit-code:
|
||||||
|
Loading…
x
Reference in New Issue
Block a user