-
Notifications
You must be signed in to change notification settings - Fork 2
149 lines (127 loc) · 4.41 KB
/
npm-audit-report.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
name: NPM Vulnerability Reports
on:
schedule:
- cron: "0 15 * * 2" # Tuesday morning at 7:00-8:00am Pacific Time.
workflow_dispatch:
# START HERE! v
# ADD REQUIRED FILES:
# - .github/helpers/parse-json5-config.js
# - .github/helpers/npm-audit/enhance-vulnerability-list.cjs
# - .github/helpers/npm-audit/find-direct-dependencies.cjs
# - .github/helpers/npm-audit/find-indirect-vulnerable-deps.cjs
# - .github/helpers/npm-audit/get-latest-dep-info.cjs
# - .github/helpers/npm-audit/is-fix-available.cjs
# - .github/helpers/npm-audit/run-npm-audit.cjs
# - .github/helpers/npm-audit/parse-npm-vulnerabilities.cjs
# - .github/helpers/npm-audit/create-report.cjs
# - .github/helpers/npm-audit/create-report-issues.cjs
# - .github/helpers/github-api/github-api-requests.cjs
# - .github/helpers/github-api/create-and-close-existing-issue.cjs
# - .github/config/vulnerability-report.json5
# EDIT .github/config/vulnerability-report.json5
# DO NOT Edit below env variables.
env:
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
jobs:
# Parse Vars from config.
parse-json5-config:
runs-on: ubuntu-22.04
outputs:
directoryPaths: ${{ steps.parse_config.outputs.directoryPaths }}
steps:
# Checkout branch.
- name: Checkout Repository
uses: actions/checkout@v4
# Install json5 npm package for parsing config.
- name: Install Dependencies
run: npm install json5
# Run script to convert json5 config to Output Vars.
- name: Run Script
id: parse_config
run: node .github/helpers/parse-json5-config.mjs .github/config/vulnerability-report.json5
# Check package versions for updates.
parse-vulnerabilities:
runs-on: ubuntu-22.04
needs: parse-json5-config
env:
directoryPaths: ${{ needs.parse-json5-config.outputs.directoryPaths }}
container:
# Lightweight NodeJS Image
image: node:21.5-bullseye-slim
steps:
# Checkout branch.
- name: Checkout repository
uses: actions/checkout@v4
# Run NodeJS script to check for latest npm dependency versions and capture output.
- name: Run NPM DEP Check Node.js script
id: check_versions
run: |
npm i -D semver
node .github/helpers/npm-audit/parse-npm-vulnerabilities.cjs > vulnerabilities.json
# Upload the output as an artifact.
- name: Upload output
uses: actions/upload-artifact@v3
with:
name: vulnerabilities
path: vulnerabilities.json
# Write the output text for the GitHub Issue.
write-output:
needs:
- parse-json5-config
- parse-vulnerabilities
runs-on: ubuntu-22.04
env:
directoryPaths: ${{ needs.parse-json5-config.outputs.directoryPaths }}
container:
# Lightweight NodeJS Image
image: node:21.5-bullseye-slim
steps:
# Checkout branch.
- name: Checkout repository
uses: actions/checkout@v4
# Download the output artifact from parse-package-versions.
- name: Download output
uses: actions/download-artifact@v3
with:
name: vulnerabilities
path: .
# Run NodeJS script to create GitHub Issue body.
- name: Run NPM DEP Check Node.js script
id: check_versions
run: |
node .github/helpers/npm-audit/create-report.cjs > outputText.json
# Upload the output as an artifact.
- name: Upload output
uses: actions/upload-artifact@v3
with:
name: outputText
path: outputText.json
# Create the GitHub Issues.
create-issues:
needs:
- parse-json5-config
- write-output
runs-on: ubuntu-22.04
env:
directoryPaths: ${{ needs.parse-json5-config.outputs.directoryPaths }}
container:
# Lightweight NodeJS Image
image: node:21.5-bullseye-slim
steps:
# Checkout branch.
- name: Checkout repository
uses: actions/checkout@v4
# Download the output artifact.
- name: Download output
uses: actions/download-artifact@v3
with:
name: outputText
path: .
# Install @octokit/rest npm package for making GitHub rest API requests.
- name: Install @octokit/rest npm
run: npm i @octokit/rest
# Run Node Script to Create GitHub Issue.
- name: Create GitHub Issues
run: |
node .github/helpers/npm-audit/create-report-issues.cjs