Skip to content

Commit c3e4aac

Browse files
authored
Update yml to latest version + synthetic config
1 parent e8f45b2 commit c3e4aac

File tree

1 file changed

+7
-11
lines changed

1 file changed

+7
-11
lines changed

code-scanning-guides/synthetic-applications/owasp-webgoat.yml

Lines changed: 7 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,6 @@ permissions:
1313
contents: read
1414
security-events: write
1515

16-
env:
17-
# Lombok support is now included by default, this is no longer needed
18-
# CODEQL_EXTRACTOR_JAVA_RUN_ANNOTATION_PROCESSORS: true
19-
2016
jobs:
2117
analyze:
2218
name: Analyze
@@ -28,34 +24,34 @@ jobs:
2824
language: [ 'java', 'javascript' ]
2925

3026
steps:
31-
- uses: actions/checkout@v2
27+
- uses: actions/checkout@v4
3228

3329
# WebGoat requires Java/JDK 17
3430
- name: Set up JDK 17
3531
if: matrix.language == 'java'
36-
uses: actions/setup-java@v3
32+
uses: actions/setup-java@v4
3733
with:
3834
distribution: 'temurin'
3935
java-version: 17
4036
architecture: x64
4137

4238
- name: Initialize CodeQL
43-
uses: github/codeql-action/init@v2
39+
uses: github/codeql-action/init@v3
4440
with:
4541
languages: ${{ matrix.language }}
4642
# [optional] enabled extended queries
4743
# queries: +security-extended,security-and-quality
4844
# [optional] Field Config - standard packs, extensions, and extra packs
49-
config-file: advanced-security/codeql-queries/config/codeql.yml@main
45+
config-file: GitHubSecurityLab/CodeQL-Community-Packs/configs/synthetics.yml@main
5046

5147
- name: Autobuild
52-
uses: github/codeql-action/autobuild@v2
48+
uses: github/codeql-action/autobuild@v3
5349

5450
# Run the Analysis
5551
- name: Perform CodeQL Analysis
56-
uses: github/codeql-action/analyze@v2
52+
uses: github/codeql-action/analyze@v3
5753

5854
# Submit Maven Dependency Tree to GitHub
5955
- name: Maven Dependency Tree Dependency Submission
6056
if: matrix.language == 'java'
61-
uses: advanced-security/maven-dependency-submission-action@v3.0.2
57+
uses: advanced-security/maven-dependency-submission-action@v3

0 commit comments

Comments
 (0)