Skip to content

Commit 779c5a8

Browse files
committed
Switch to composite action approach for security scan
Cross-org reusable workflows not supported, use composite action instead. Co-authored-by: Isaac
1 parent dd8238c commit 779c5a8

File tree

1 file changed

+5
-12
lines changed

1 file changed

+5
-12
lines changed

.github/workflows/security-scan.yml

Lines changed: 5 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ on:
77
- java-security
88

99
jobs:
10-
build:
10+
build-and-scan:
1111
runs-on: ubuntu-latest
1212
steps:
1313
- name: Checkout
@@ -28,15 +28,8 @@ jobs:
2828
- name: Build JAR
2929
run: mvn --errors package -DskipTests -pl databricks-sdk-java
3030

31-
- name: Upload build artifact
32-
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
31+
- name: Security scan
32+
uses: databricks-eng/gh-action-scan@v1.0.0
3333
with:
34-
name: build-artifact
35-
path: databricks-sdk-java/target/*.jar
36-
37-
security-scan:
38-
needs: build
39-
uses: databricks-eng/gh-action-scan/.github/workflows/scan.yml@v1.0.0
40-
with:
41-
download-artifact: build-artifact
42-
artifact-name: databricks-sdk-java
34+
artifact-path: databricks-sdk-java/target/
35+
artifact-name: databricks-sdk-java

0 commit comments

Comments
 (0)