Skip to content

Bump pillow from 10.0.1 to 10.2.0 in /requirements #279

Bump pillow from 10.0.1 to 10.2.0 in /requirements

Bump pillow from 10.0.1 to 10.2.0 in /requirements #279

# This workflow integrates Scan with GitHub's code scanning feature
# Scan is a free open-source security tool for modern DevOps teams from ShiftLeft
# Visit https://slscan.io/en/latest/integrations/code-scan for help
name: ShiftLeft Code Scan
on:
pull_request:
branches:
- master
push:
branches:
- master
workflow_dispatch:
jobs:
Scan-Build:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v3
with:
fetch-depth: 2
- run: git checkout HEAD^2
if: ${{ github.event_name == 'pull_request' }}
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.10'
cache: 'pip'
- name: Cache pip
id: cache
uses: actions/cache@v3
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ hashFiles('requirements/dev.txt') }}
restore-keys: |
${{ runner.os }}-pip-
${{ runner.os }}-
- name: Set up requirements
run: pip install -r requirements/dev.txt
- name: Perform scan
uses: ShiftLeftSecurity/scan-action@master
env:
WORKSPACE: ""
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SCAN_AUTO_BUILD: true
with:
output: reports
type: "python,credscan,depscan"
- name: Upload report
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: reports