Skip to content

Commit 6839482

Browse files
meysholdtona-agent
andcommitted
Add Maven dependency submission workflow
Resolves full dependency tree with versions so Dependabot can match against known CVEs. Co-authored-by: Ona <no-reply@ona.com>
1 parent da7a66b commit 6839482

1 file changed

Lines changed: 27 additions & 0 deletions

File tree

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
name: Maven Dependency Submission
2+
3+
on:
4+
push:
5+
branches: [ "main" ]
6+
paths:
7+
- 'pom.xml'
8+
- '.mvn/**'
9+
workflow_dispatch:
10+
11+
permissions:
12+
contents: write
13+
14+
jobs:
15+
submit:
16+
runs-on: ubuntu-latest
17+
steps:
18+
- uses: actions/checkout@v4
19+
20+
- name: Set up JDK 17
21+
uses: actions/setup-java@v4
22+
with:
23+
java-version: '17'
24+
distribution: 'adopt'
25+
26+
- name: Submit dependency graph
27+
uses: advanced-security/maven-dependency-submission-action@v4

0 commit comments

Comments
 (0)