From 916e00e5c7f88047b15da55b87c16b620e635361 Mon Sep 17 00:00:00 2001 From: Josh Stegmaier <104993387+joshuastegmaier@users.noreply.github.com> Date: Mon, 5 Feb 2024 09:12:48 -0500 Subject: [PATCH] Added pip-audit to Github workflow (#2260) * Added pip-audit Github workflow * Modified pip-audit * Changed branch name * Modified pip-audit.yml * Modified pip-audit.yml * Modified pip-audit.yml * Modified pip-audit.yml --- .github/workflows/pip-audit.yml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/workflows/pip-audit.yml diff --git a/.github/workflows/pip-audit.yml b/.github/workflows/pip-audit.yml new file mode 100644 index 000000000..1500cb44a --- /dev/null +++ b/.github/workflows/pip-audit.yml @@ -0,0 +1,25 @@ +name: pip-audit + +on: + workflow_dispatch: + push: + branches: [main, release] + pull_request: + branches: [main] + +jobs: + pip-audit: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-python@v4 + with: + python-version: '3.10' + + - name: 'Generate requirements.txt' + run: | + pipx run pipfile-requirements Pipfile.lock > requirements.txt + + - uses: pypa/gh-action-pip-audit@v1.0.8 + with: + inputs: requirements.txt