From cb9898707305f83ad2feca68bf00f20129d5dbdd Mon Sep 17 00:00:00 2001 From: Quentin Decaunes Date: Sun, 10 Mar 2019 16:24:31 +0100 Subject: [PATCH] Added dependency_scanning jobs. --- .gitlab-ci.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 3a48893..6b7a822 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -1,8 +1,30 @@ stages: + - check - install - package - installer +dependency_scanning: + stage: check + only: + - branches@le.storm1er/ryzen-controller + image: docker:stable + variables: + DOCKER_DRIVER: overlay2 + allow_failure: true + services: + - docker:stable-dind + script: + - export SP_VERSION=$(echo "$CI_SERVER_VERSION" | sed 's/^\([0-9]*\)\.\([0-9]*\).*/\1-\2-stable/') + - docker run + --env DEP_SCAN_DISABLE_REMOTE_CHECKS="${DEP_SCAN_DISABLE_REMOTE_CHECKS:-false}" + --volume "$PWD:/code" + --volume /var/run/docker.sock:/var/run/docker.sock + "registry.gitlab.com/gitlab-org/security-products/dependency-scanning:$SP_VERSION" /code + artifacts: + reports: + dependency_scanning: gl-dependency-scanning-report.json + node: only: - tags@le.storm1er/ryzen-controller