From 5558cf6b7ea39e6cbf491d413305c01e587f837f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 12 May 2021 05:04:41 +0000 Subject: [PATCH] Bump actions/setup-java from 1 to 2 Bumps [actions/setup-java](https://github.com/actions/setup-java) from 1 to 2. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](https://github.com/actions/setup-java/compare/v1...v2) Signed-off-by: dependabot[bot] --- .github/workflows/fortify-analysis.yml | 2 +- .github/workflows/veracode-analysis.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/fortify-analysis.yml b/.github/workflows/fortify-analysis.yml index 03ddf91..bf1c5f8 100644 --- a/.github/workflows/fortify-analysis.yml +++ b/.github/workflows/fortify-analysis.yml @@ -40,7 +40,7 @@ jobs: if: ${{ github.event_name == 'pull_request' }} # Java 8 required by ScanCentral Client and FoD Uploader(Univeral CI Tool) - name: Setup Java - uses: actions/setup-java@v1 + uses: actions/setup-java@v2 with: java-version: 1.8 diff --git a/.github/workflows/veracode-analysis.yml b/.github/workflows/veracode-analysis.yml index f56937a..3f0e296 100644 --- a/.github/workflows/veracode-analysis.yml +++ b/.github/workflows/veracode-analysis.yml @@ -40,7 +40,7 @@ jobs: args: -O https://downloads.veracode.com/securityscan/pipeline-scan-LATEST.zip - run: unzip -o pipeline-scan-LATEST.zip - - uses: actions/setup-java@v1 + - uses: actions/setup-java@v2 with: java-version: 1.8 - run: java -jar pipeline-scan.jar --veracode_api_id "${{secrets.VERACODE_API_ID}}" --veracode_api_key "${{secrets.VERACODE_API_KEY}}" --fail_on_severity="Very High, High" --file veracode-pipeline-scan-results-to-sarif.zip