Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
152 commits
Select commit Hold shift + click to select a range
f2e02d5
Update veracodefix.yml
julz0815 Apr 24, 2024
b090497
Update veracodefix.yml
julz0815 Apr 27, 2024
f50b973
Update veracodefix.yml
julz0815 May 22, 2024
282f7c6
Update veracodefix.yml
julz0815 May 22, 2024
189ce69
Update veracodefix.yml
julz0815 May 25, 2024
bab3600
Update veracodefix.yml
julz0815 May 26, 2024
918aefe
Update veracodefix.yml
julz0815 May 27, 2024
62ad995
Update veracodefix.yml
julz0815 May 27, 2024
7130a9f
Update veracodefix.yml
julz0815 May 31, 2024
4b4fa36
Update veracodefix.yml
julz0815 May 31, 2024
b217eca
Update veracodefix.yml
julz0815 May 31, 2024
096124c
Update veracodefix.yml
julz0815 Jun 3, 2024
dddd347
Update veracodefix.yml
julz0815 Jun 3, 2024
2171b2d
Update veracodefix.yml
julz0815 Jun 3, 2024
2bc58e6
Update veracodefix.yml
julz0815 Jun 3, 2024
5918d25
Update scascan.yml
julz0815 Sep 20, 2024
16880ea
Update scascan.yml
julz0815 Sep 20, 2024
f656f4b
Update veracodefix.yml
julz0815 Oct 15, 2024
a5a579d
Update veracodefix.yml
julz0815 Feb 6, 2025
748b3ef
Update veracodefix.yml
julz0815 Feb 6, 2025
ac3665e
Update veracodefix.yml
julz0815 Feb 6, 2025
987e7a0
Merge pull request #1307 from julz0815/julz0815-patch-1
julz0815 Feb 6, 2025
2a7e2dc
Update scascan.yml
julz0815 Feb 7, 2025
e4cdfd8
Update scascan.yml
julz0815 Feb 7, 2025
ceb4571
Update scascan.yml
julz0815 Feb 7, 2025
af22dd9
Update scascan.yml
julz0815 Feb 8, 2025
2e85518
Merge pull request #1308 from julz0815/julz0815-patch-2
julz0815 Feb 8, 2025
5163214
Update scascan.yml
julz0815 Feb 8, 2025
1f24e97
Update importflaws.yml
julz0815 Apr 8, 2025
3505271
Update importflaws.yml
julz0815 Apr 8, 2025
d3e35a6
Update importflaws.yml
julz0815 Apr 8, 2025
aff2b58
Update importflaws.yml
julz0815 Apr 8, 2025
128d603
Update importflaws.yml
julz0815 Apr 8, 2025
23ca636
Update importflaws.yml
julz0815 Apr 8, 2025
e0beb68
Update importflaws.yml
julz0815 Apr 8, 2025
ae7d0ea
Update importflaws.yml
julz0815 Apr 8, 2025
fbb719c
Update UserController.java
julz0815 Apr 8, 2025
b4807a1
Update policyscan.yml
julz0815 Apr 8, 2025
4fcddd8
Update policyscan.yml
julz0815 Apr 8, 2025
b810d82
Update pipelinescan.yaml
julz0815 Apr 8, 2025
719fed3
Update pipelinescan.yaml
julz0815 Apr 8, 2025
b2e7d61
Update pipelinescan.yaml
julz0815 Apr 8, 2025
28cb764
Update pipelinescan.yaml
julz0815 Apr 8, 2025
622391e
Update pipelinescan.yaml
julz0815 Apr 8, 2025
d0d57c6
Update pipelinescan.yaml
julz0815 Apr 8, 2025
94f7482
Update pipelinescan.yaml
julz0815 Apr 8, 2025
4060161
Update pipelinescan.yaml
julz0815 Apr 8, 2025
d71c009
Update importflaws.yml
julz0815 May 29, 2025
1ee4a5a
Create backgroundnotifier.yml
julz0815 Jul 16, 2025
c0893d1
Update backgroundnotifier.yml
julz0815 Jul 16, 2025
617434d
Update containerscan.yml
julz0815 Aug 14, 2025
cd67067
Update containerscan.yml
julz0815 Aug 14, 2025
fcb74a6
Update Veracode fix action and parameters
julz0815 Sep 5, 2025
c606bbc
Disable PR creation in veracodefix workflow
julz0815 Sep 5, 2025
f886726
Enable GitHub App usage in veracodefix workflow
julz0815 Sep 7, 2025
e886ab4
Enable PR creation in veracodefix workflow
julz0815 Sep 7, 2025
607d826
Enable build failure on Veracode scan failure
julz0815 Sep 7, 2025
1f098ff
Update conditional syntax for 'if' statement
julz0815 Sep 7, 2025
3ccc34e
Update importflaws.yml
julz0815 Sep 26, 2025
655df31
Update importflaws.yml
julz0815 Sep 26, 2025
331c541
Add conditional execution for import-policy-flaws job
julz0815 Sep 26, 2025
0f8bb6d
Fix path for scan results JSON in workflow
julz0815 Sep 26, 2025
0a1a950
Disable folder listing in importflaws workflow
julz0815 Sep 26, 2025
bed38ee
Uncomment get-policy-flaws job in workflow
julz0815 Oct 1, 2025
821b847
Update import-policy-flaws job dependencies and paths
julz0815 Oct 1, 2025
d7d720e
Uncomment artifact name in importflaws.yml
julz0815 Oct 1, 2025
a7fe0c4
Enable auto-close findings in importflaws workflow
julz0815 Oct 8, 2025
0fb4e03
Comment out ADO settings in importflaws.yml
julz0815 Oct 8, 2025
d38e063
Update GUID retrieval in importflaws.yml
julz0815 Oct 8, 2025
f569c07
Update GUID for Veracode API call in workflow
julz0815 Oct 8, 2025
3a5f2b2
Uncomment GUID retrieval in importflaws.yml
julz0815 Oct 8, 2025
684806c
Update GUID retrieval method in importflaws.yml
julz0815 Oct 8, 2025
07294d0
Retrieve application GUID dynamically in workflow
julz0815 Oct 8, 2025
598bd07
Update Veracode API call to use static GUID
julz0815 Oct 8, 2025
f26c5a8
Retrieve GUID dynamically instead of hardcoding
julz0815 Oct 8, 2025
ead7bd0
Update importflaws.yml
julz0815 Oct 8, 2025
a3f1f09
Uncomment GUID retrieval from Veracode API
julz0815 Oct 8, 2025
e61392d
Update GUID retrieval method in importflaws.yml
julz0815 Oct 8, 2025
1df76c4
Enable dynamic GUID retrieval in workflow
julz0815 Oct 8, 2025
2c03762
Update GUID retrieval method in importflaws.yml
julz0815 Oct 8, 2025
8612dff
Uncomment GUID retrieval from Veracode API
julz0815 Oct 8, 2025
474d936
Update Veracode API GUID retrieval method
julz0815 Oct 8, 2025
7f0b224
Add files via upload
julz0815 Oct 9, 2025
0bb5807
Change scan results JSON file name in workflow
julz0815 Oct 9, 2025
adb2434
Add checkout step to importflaws workflow
julz0815 Oct 9, 2025
9cc524b
Update scan results JSON filename in workflow
julz0815 Oct 9, 2025
9ae431a
Update scan results JSON file name in workflow
julz0815 Oct 10, 2025
31cdd2e
Update scan results JSON file name
julz0815 Oct 10, 2025
677b0e3
Add include_annot parameter to Veracode API calls
julz0815 Oct 11, 2025
05456f7
Change scan results JSON file path in workflow
julz0815 Oct 11, 2025
a872331
Remove include_annot parameter from API request
julz0815 Oct 11, 2025
0301e6e
Update Veracode API calls to include annotations
julz0815 Oct 28, 2025
59416f3
Comment out build steps in importflaws.yml
julz0815 Oct 28, 2025
2156cce
Fix application name in Veracode API call
julz0815 Oct 28, 2025
6442c28
Remove hardcoded GUID from importflaws.yml
julz0815 Oct 28, 2025
6e1a450
Uncomment API call to retrieve application GUID
julz0815 Oct 28, 2025
23fee4b
Modify ADO project and work item type in workflow
julz0815 Oct 29, 2025
abf1fc2
Change application name in Veracode API call
julz0815 Oct 30, 2025
6789f6b
Update policyscan.yml
julz0815 Nov 10, 2025
250372c
Update Veracode action version in workflow
julz0815 Nov 10, 2025
45e4c25
Update Veracode action version in workflow
julz0815 Nov 10, 2025
c7dc6aa
Update policyscan.yml
julz0815 Nov 10, 2025
8d8d997
Update filepath for policy scan in workflow
julz0815 Nov 11, 2025
232b4c5
Change filepath to target directory in policyscan.yml
julz0815 Nov 11, 2025
53288c4
Update scascan.yml
julz0815 Nov 23, 2025
fd19d33
Create policyscan2.yml
julz0815 Dec 15, 2025
a42758f
Remove build job from policyscan2 workflow
julz0815 Dec 15, 2025
c05c4c5
Update file path in policyscan2.yml
julz0815 Dec 15, 2025
a1e3015
Update policyscan2.yml
julz0815 Dec 15, 2025
0da7735
Change Veracode SCA action and disable debug
julz0815 Dec 16, 2025
defdcbc
Merge pull request #2182 from julz0815/julz0815-patch-6
julz0815 Dec 16, 2025
bbcf747
Enable debug mode in SCA scan workflow
julz0815 Dec 16, 2025
55e702d
Update container scan action to add policy support
julz0815 Jan 6, 2026
e1279e8
Fix casing in container scan action reference
julz0815 Jan 6, 2026
bab9161
Update containerscan.yml
julz0815 Jan 6, 2026
0ac3df5
Refactor container scan workflow by removing steps
julz0815 Jan 6, 2026
3ab152a
Add policy for container scan
julz0815 Jan 6, 2026
311dff3
Refactor GitHub Actions workflow for policy flaws
julz0815 Jan 10, 2026
19a6b34
Add sandbox name to Veracode workflow
julz0815 Jan 10, 2026
d439627
Comment out sandbox-name in importflaws.yml
julz0815 Jan 10, 2026
4ef7908
Change debug mode from true to false
julz0815 Jan 12, 2026
9a6676a
Update Veracode profile name in workflow
julz0815 Jan 21, 2026
69076c7
Enable debug mode in importflaws workflow
julz0815 Jan 21, 2026
c00eb48
Uncomment Veracode flaws import configuration
julz0815 Jan 23, 2026
a2ce17b
Add Veracode DAST workflow configuration
julz0815 Jan 23, 2026
0edf533
Update Veracode DAST action to new repository
julz0815 Jan 23, 2026
35da116
Rename profile to profile_name in dast.yml
julz0815 Jan 23, 2026
0dffcf6
Update Veracode DAST scan credentials
julz0815 Jan 23, 2026
64ec657
Add workflow to import policy flaws as issues
julz0815 Jan 29, 2026
c185584
Fix typo in GitHub Actions workflow file
julz0815 Jan 29, 2026
d06554b
Fix token key format in ADO workflow
julz0815 Jan 29, 2026
02f6829
Update area and iteration paths in workflow config
julz0815 Jan 29, 2026
85f68fb
Change ado-workitems-action version and states
julz0815 Jan 29, 2026
34369ce
Fix action reference in ado-workitems.yml
julz0815 Jan 29, 2026
9f02192
Update Veracode app profile in workflow
julz0815 Jan 29, 2026
d363344
Add CWE 117 to Veracode fix configuration
julz0815 Feb 12, 2026
c08894a
Update veracodefix.yml
julz0815 Feb 12, 2026
f5bf700
Change CWE ID from 117 to 89 in workflow
julz0815 Feb 12, 2026
9e85f09
Change useGitHubApp setting to false
julz0815 Feb 12, 2026
15f20b4
Remove CWE '89' from Veracode fix configuration
julz0815 Feb 12, 2026
60b7d64
Add language parameter to Veracode fix workflow
julz0815 Feb 12, 2026
8fc5b04
Add source base paths for Veracode fix workflow
julz0815 Feb 12, 2026
44768c8
Add CWE-89 to Veracode fix configuration
julz0815 Feb 12, 2026
901146b
Update Veracode fix action to use workflowApp
julz0815 Feb 12, 2026
6b24efe
Merge c723c9aa3ad6695476c63535203e6284910a4558 into 901146b722c875af8…
julz0815 Feb 12, 2026
76cd8ba
Veracode-Fix-Bot - update src/main/java/com/veracode/verademo/control…
invalid-email-address Feb 12, 2026
241146f
Veracode-Fix-Bot - update src/main/java/com/veracode/verademo/control…
invalid-email-address Feb 12, 2026
f3fd453
Veracode-Fix-Bot - update src/main/java/com/veracode/verademo/command…
invalid-email-address Feb 12, 2026
dbd7ff5
Veracode-Fix-Bot - update src/main/java/com/veracode/verademo/command…
invalid-email-address Feb 12, 2026
86b7993
Veracode-Fix-Bot - update src/main/java/com/veracode/verademo/command…
invalid-email-address Feb 12, 2026
8adbd28
test commit
julz0815 Feb 24, 2026
81f0677
test commit
julz0815 Feb 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .github/workflows/ado-workitems.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
on:
workflow_dispatch:

jobs:
import-policy-flaws:
runs-on: ubuntu-latest
steps:

- name: import flaws as issues
uses: julz0815/ado-workitems-action@api_and_close
with:
ado-token: ${{ secrets.ADO_PAT }}
ado-org: jtotzek
ado-project: MeijerTest
work-item-type: Bug
area-path: "MeijerTest"
iteration-path: "MeijerTest"
open-state: New
close-state: Closed
repopen-state: New
veracode-api-id: ${{ secrets.VID }}
veracode-api-key: ${{ secrets.VKEY }}
veracode-app-profile: "test-action"
scan-type: "Static Analysis and SCA"
import-type: "All Unmitigated Flaws Violating Policy"
68 changes: 68 additions & 0 deletions .github/workflows/backgroundnotifier.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
on:
# pull_request:
# branches: [main]
workflow_dispatch:



jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-java@v3
with:
distribution: 'zulu'
java-version: 8
- name: Cache Maven packages
uses: actions/cache@v3
with:
path: ~/.m2
key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
- name: Build with Maven
run: mvn clean package

- uses: actions/upload-artifact@v4
with:
name: verademo.war
path: target/verademo.war

pipeline_scan:
needs: build
runs-on: ubuntu-latest
name: pipeline scan
steps:
- name: Background timer notifier
run: |
(
i=0
while true; do
i=$((i+1))
curl -X POST -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \
-H "Accept: application/vnd.github.v3+json" \
https://api.github.com/repos/${{ github.repository }}/issues/1/comments \
-d "{\"body\":\"⏱️ Job running for $((i * 1)) minutes...\"}"
sleep 60
done
) &
- name: checkout repo
uses: actions/checkout@v3

- name: get archive
uses: actions/download-artifact@v4
with:
name: verademo.war
- name: pipeline-scan action step
id: pipelien-scan
uses: veracode/[email protected]
with:
vid: ${{ secrets.VID }}
vkey: ${{ secrets.VKEY }}
#file: "auth.js.zip"
file: "verademo.war"
request_policy: "VeraDemo Policy"
#store_baseline_file: true
#store_baseline_file_branch: "feature-123"
#create_baseline_from: "standard"
debug: 1
fail_build: false
5 changes: 3 additions & 2 deletions .github/workflows/containerscan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,10 +13,10 @@ jobs:
steps:
- name: checkout
uses: actions/checkout@v2

- name: container-scan action step
id: container-scan
uses: veracode/container_iac_secrets_scanning@v1.0.1
uses: veracode/container_iac_secrets_scanning@addPolicySupport
with:
vid: ${{ secrets.VID }}
vkey: ${{ secrets.VKEY }}
Expand All @@ -26,3 +26,4 @@ jobs:
format: "json"
debug: true
fail_build: true
policy: "Container/IaC/Secrets"
17 changes: 17 additions & 0 deletions .github/workflows/dast.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
on:
workflow_dispatch:

name: Veracode DAST

jobs:
Submit-DAST-Scan:
runs-on: ubuntu-latest
steps:
- name: Submit Veracode DAST Scan
uses: veracode/veracode-dast-action@resultsToIssues
with:
vid: ${{ secrets.VID }}
vkey: ${{ secrets.VKEY }}
action_type: load-results
profile_name: "Verademo API"
token: ${{ secrets.GITHUB_TOKEN }}
126 changes: 96 additions & 30 deletions .github/workflows/importflaws.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,27 +6,75 @@ on:
# - feature-123

jobs:
get-policy-flaws:
runs-on: ubuntu-latest
container:
image: veracode/api-signing:latest
steps:
- name: get policy flaws
run: |
cd /tmp
export VERACODE_API_KEY_ID=${{ secrets.VID }}
export VERACODE_API_KEY_SECRET=${{ secrets.VKEY }}
guid=$(http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v1/applications?name=test-action" | jq -r '._embedded.applications[0].guid')
echo GUID: ${guid}
total_flaws=$(http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v2/applications/${guid}/findings?scan_type=STATIC&violates_policy=True" | jq -r '.page.total_elements')
echo TOTAL_FLAWS: ${total_flaws}
http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v2/applications/${guid}/findings?scan_type=STATIC&violates_policy=True&size=${total_flaws}" > policy_flaws.json
# build:
# runs-on: ubuntu-latest
# steps:
# - uses: actions/checkout@v3
# - uses: actions/setup-java@v3
# with:
# distribution: 'zulu'
# java-version: 8
## - name: Cache Maven packages
## uses: actions/cache@v3
## with:
## path: ~/.m2
## key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
# - name: Build with Maven
# run: mvn clean package

- name: save results file
uses: actions/upload-artifact@v3
with:
name: policy-flaws
path: /tmp/policy_flaws.json
# - uses: actions/upload-artifact@v4
# with:
# name: verademo.war
# path: target/verademo.war

# pipeline_scan:
# needs: build
# runs-on: ubuntu-latest
# name: pipeline scan
# steps:
# - name: checkout repo
# uses: actions/checkout@v3

# - name: get archive
# uses: actions/download-artifact@v4
# with:
# name: verademo.war
# - name: pipeline-scan action step
# id: pipelien-scan
# uses: veracode/Veracode-pipeline-scan-action@esd-true
# with:
# vid: ${{ secrets.VID }}
# vkey: ${{ secrets.VKEY }}
# file: "verademo.war"
# request_policy: "VeraDemo Policy"
# debug: 1
# fail_build: true



# get-policy-flaws:
# runs-on: ubuntu-latest
# continue-on-error: true
# container:
# image: veracode/api-signing:latest
# steps:
# - name: get policy flaws
# run: |
# cd /tmp
# export VERACODE_API_KEY_ID=${{ secrets.VID }}
# export VERACODE_API_KEY_SECRET=${{ secrets.VKEY }}
# guid=$(http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v1/applications?name=test-app1" | jq -r '._embedded.applications[0].guid')
# echo GUID: ${guid}
# total_flaws=$(http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v2/applications/${guid}/findings?scan_type=STATIC&violates_policy=True&include_annot=TRUE" | jq -r '.page.total_elements')
# echo TOTAL_FLAWS: ${total_flaws}
# http --auth-type veracode_hmac GET "https://api.veracode.com/appsec/v2/applications/${guid}/findings?scan_type=STATIC&violates_policy=True&size=${total_flaws}&include_annot=TRUE" > policy_flaws.json

# - name: save results file
# uses: actions/upload-artifact@v4
# with:
# name: policy-flaws
# path: /tmp/policy_flaws.json


# results_to_security_tab:
# needs: get-policy-flaws
Expand All @@ -51,19 +99,37 @@ jobs:
# source_base_path_2: "WEB-INF:src/main/webapp/WEB-INF"

import-policy-flaws:
needs: get-policy-flaws
# needs: get-policy-flaws
runs-on: ubuntu-latest
# if: always()
steps:
- name: get flaw file
uses: actions/download-artifact@v3
with:
name: policy-flaws
path: /tmp
# - uses: actions/checkout@v3
# - name: get flaw file
# uses: actions/download-artifact@v4
# with:
# name: policy-flaws
# path: /tmp

#- name: Show folder
# run: |
# ls -laR /tmp

- name: import flaws as issues
uses: veracode/veracode-flaws-to-issues@FixEmptyResults
uses: veracode/veracode-flaws-to-issues@ADO_workitems
with:
dts_type: ADO
ADO_PAT: ${{ secrets.ADO_PAT }}
ADO_ORG: jtotzek
ADO_PROJECT: MeijerTest
ADO_WORK_ITEM_TYPE: Bug
ADO_OPEN_STATE: New
ADO_CLOSE_STATE: Closed
ADO_REOPEN_STATE: New
scan-results-json: '/tmp/policy_flaws.json'
# debug: true
source_base_path_1: "com/:src/main/java/com/"
source_base_path_2: "WEB-INF:src/main/webapp/WEB-INF"
veracode-api-id: ${{ secrets.VID }}
veracode-api-key: ${{ secrets.VKEY }}
profile-name: "julian-veracode/python-test-repo"
#sandbox-name: "Feature123"
include-sca: true
autoCloseFindings: true
debug: true
55 changes: 28 additions & 27 deletions .github/workflows/pipelinescan.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
- name: Build with Maven
run: mvn clean package

- uses: actions/upload-artifact@v3
- uses: actions/upload-artifact@v4
with:
name: verademo.war
path: target/verademo.war
Expand All @@ -36,12 +36,12 @@ jobs:
uses: actions/checkout@v3

- name: get archive
uses: actions/download-artifact@v3
uses: actions/download-artifact@v4
with:
name: verademo.war
- name: pipeline-scan action step
id: pipelien-scan
uses: veracode/[email protected].12
uses: veracode/[email protected].18
with:
vid: ${{ secrets.VID }}
vkey: ${{ secrets.VKEY }}
Expand All @@ -54,41 +54,42 @@ jobs:
debug: 1
fail_build: false

results_to_sarif:
needs: pipeline_scan
runs-on: ubuntu-latest
name: import pipeline results to sarif
steps:
- name: get flaw file
uses: actions/download-artifact@v2
with:
name: Veracode Pipeline-Scan Results
- name: Convert pipeline scan output to SARIF format
id: convert
uses: Veracode/veracode-pipeline-scan-results-to-sarif@support-saf-scanners
#uses: Veracode/[email protected]
with:
pipeline-results-json: results.json
output-results-sarif: veracode-results.sarif
# results_to_sarif:
# needs: pipeline_scan
# runs-on: ubuntu-latest
# name: import pipeline results to sarif
# steps:
# - name: get flaw file
# uses: actions/download-artifact@v2
# with:
# name: Veracode Pipeline-Scan Results
# - name: Convert pipeline scan output to SARIF format
# id: convert
# uses: Veracode/veracode-pipeline-scan-results-to-sarif@support-saf-scanners
# #uses: Veracode/[email protected]
# with:
# pipeline-results-json: results.json
# output-results-sarif: veracode-results.sari

- name: upload sarif file to repository
uses: github/codeql-action/upload-sarif@v2
with: # Path to SARIF file relative to the root of the repository
sarif_file: veracode-results.sarif
# - name: upload sarif file to repository
# uses: github/codeql-action/upload-sarif@v2
# with: # Path to SARIF file relative to the root of the repository
# sarif_file: veracode-results.sarif

# This step will import flaws from the step above
import-pipeline-flaws:
needs: pipeline_scan
runs-on: ubuntu-latest
steps:
- name: get flaw file
uses: actions/download-artifact@v2
uses: actions/download-artifact@v4
with:
name: Veracode Pipeline-Scan Results
#name: Veracode Pipeline-Scan Results -
path: /tmp

- name: import flaws as issues
uses: veracode/veracode-flaws-to-issues@v2.1.18
uses: veracode/veracode-flaws-to-issues@closeIssues
with:
scan-results-json: '/tmp/filtered_results.json'
scan-results-json: '/tmp/Veracode Pipeline-Scan Results - /filtered_results.json'
debug: true

Loading