# This workflow uses actions that are not certified by GitHub. # They are provided by a third-party and are governed by # separate terms of service, privacy policy, and support # documentation. # OSV-Scanner for detecting vulnerabilities in dependencies. # Runs on PRs to catch vulnerable dependencies before merge (shift-left security). # # NOTE: This workflow is NOT included in release-gate.yml because # GitHub Actions limits reusable workflow nesting to 2 levels. Since this # workflow calls google/osv-scanner-reusable.yml, including it in the gate # would create 4 levels of nesting and cause startup_failure: # release.yml → release-gate.yml → osv-scanner.yml → google/osv-scanner-reusable.yml # # For more examples and options, including how to ignore specific vulnerabilities, # see https://google.github.io/osv-scanner/github-action/ name: OSV-Scanner on: pull_request: branches: [ "main" ] merge_group: branches: [ "main" ] schedule: - cron: '39 12 * * 1' # Weekly scan for newly disclosed CVEs workflow_dispatch: # No concurrency group — intentionally omitted. # Previous attempt (#3554, reverted #3599) used cancel-in-progress which # killed in-progress PR runs before they produced useful results. # Future iteration could safely add concurrency for scheduled/push-only # triggers (where head_ref is empty and runs get unique groups). permissions: {} # Minimal top-level for OSSF Scorecard Token-Permissions jobs: scan: permissions: security-events: write contents: read actions: read uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@9a498708959aeaef5ef730655706c5a1df1edbc2" # v2.3.8 with: scan-args: |- -r --skip-git ./