diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 763c62d7e..14a4551ef 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -6,21 +6,13 @@ on: workflow_dispatch: jobs: - analyze: - name: Code Scanning - CodeQL - runs-on: ubuntu-latest - timeout-minutes: 25 - permissions: - security-events: write - packages: read - actions: read - contents: read + codeql-java: strategy: fail-fast: false - steps: - - uses: hyperwallet/public-security-workflows/codeql@main - with: - language: java - build-mode: 'none' - timeout-minutes: 25 - + uses: hyperwallet/public-security-workflows/.github/workflows/codeql-java.yml@main + with: + language: java + build-command: 'none' + timeout-minutes: 25 + secrets: + DATADOG_API_KEY: ${{ secrets.DATADOG_PAYPAL_QA_TOKEN }} \ No newline at end of file diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 15a228e1f..f27b96b83 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,10 +1,15 @@ -name: CodeQL Dependency Review - SCA +name: Dependency Review on: - pull_request: push: + branches: ['master'] + + pull_request: + branches: [ master ] workflow_dispatch: jobs: dependency-review: - uses: hyperwallet/public-security-workflows/commit-status@main + uses: hyperwallet/public-security-workflows/.github/workflows/dependency-review.yml@main + secrets: + DATADOG_API_KEY: ${{ secrets.DATADOG_PAYPAL_QA_TOKEN }} \ No newline at end of file