diff --git a/.github/workflows/backend.yml b/.github/workflows/backend.yml
index b9e707b879..52ccc6c431 100644
--- a/.github/workflows/backend.yml
+++ b/.github/workflows/backend.yml
@@ -67,7 +67,7 @@ jobs:
with:
submodules: true
- name: Set up JDK ${{ matrix.java }}
- uses: actions/setup-java@v2
+ uses: actions/setup-java@v4
with:
java-version: ${{ matrix.java }}
distribution: 'adopt'
@@ -160,7 +160,7 @@ jobs:
version: ["3.1.9", "3.2.0"]
steps:
- name: Set up JDK 8
- uses: actions/setup-java@v2
+ uses: actions/setup-java@v4
with:
java-version: 8
distribution: 'adopt'
diff --git a/.github/workflows/owasp-dependency-check.yaml b/.github/workflows/owasp-dependency-check.yaml
index b4ee52c57d..dc6d02a4b3 100644
--- a/.github/workflows/owasp-dependency-check.yaml
+++ b/.github/workflows/owasp-dependency-check.yaml
@@ -22,7 +22,7 @@ on:
branches:
- '[0-9]+.[0-9]+.[0-9]+-prepare'
- '[0-9]+.[0-9]+.[0-9]+-release'
- pull_request:
+ pull_request_target:
paths:
- '**/pom.xml'
env:
@@ -30,6 +30,9 @@ env:
jobs:
build:
+ permissions:
+ contents: read
+ pull-requests: write
runs-on: ubuntu-latest
timeout-minutes: 120
steps:
@@ -37,12 +40,18 @@ jobs:
with:
submodules: true
- name: Set up JDK 8
- uses: actions/setup-java@v2
+ uses: actions/setup-java@v4
with:
java-version: 8
distribution: 'adopt'
- name: Run OWASP Dependency Check
- run: ./mvnw -B clean install verify dependency-check:check -DskipDepCheck=false -Dmaven.test.skip=true -Dspotless.skip=true
+ run: |
+ ./mvnw -B clean install verify dependency-check:check \
+ -DskipDepCheck=false \
+ -Dmaven.test.skip=true \
+ -Dspotless.skip=true
+ env:
+ NIST_NVD_API_KEY: ${{ secrets.NIST_NVD_API_KEY }}
- name: Upload report
uses: actions/upload-artifact@v4
if: ${{ cancelled() || failure() }}
diff --git a/.github/workflows/unit-test.yml b/.github/workflows/unit-test.yml
index e4e413d216..24bfdabe02 100644
--- a/.github/workflows/unit-test.yml
+++ b/.github/workflows/unit-test.yml
@@ -66,7 +66,7 @@ jobs:
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: Set up JDK ${{ matrix.java }}
- uses: actions/setup-java@v2
+ uses: actions/setup-java@v4
with:
java-version: ${{ matrix.java }}
distribution: 'adopt'
@@ -95,7 +95,7 @@ jobs:
restore-keys: ${{ runner.os }}-maven-
# Set up JDK 17 for SonarCloud.
- name: Set up JDK 17
- uses: actions/setup-java@v2
+ uses: actions/setup-java@v4
with:
java-version: 17
distribution: 'adopt'
diff --git a/pom.xml b/pom.xml
index 47b1fdef00..7f7bfdda76 100755
--- a/pom.xml
+++ b/pom.xml
@@ -86,7 +86,7 @@
false
3.2.0
3.0.0
- 9.2.0
+ 10.0.2
1.18.20
4.2.0
1.4.2
@@ -545,6 +545,7 @@
true
true
7
+ NIST_NVD_API_KEY