@@ -14,7 +14,7 @@ permissions:
1414jobs :
1515 docker-scan :
1616 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'docker-scan' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-docker-scan'
17- runs-on : ubuntu-22 .04
17+ runs-on : ubuntu-24 .04
1818 timeout-minutes : 60
1919 steps :
2020 - name : trivy
2424
2525 enrich :
2626 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'enrich' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-enrichment-code'
27- runs-on : ubuntu-22 .04
27+ runs-on : ubuntu-24 .04
2828 timeout-minutes : 60
2929 steps :
3030 - name : enrichment
3434
3535 iac-misconfig-detection-cloudformation :
3636 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-cloudformation' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
37- runs-on : ubuntu-22 .04
37+ runs-on : ubuntu-24 .04
3838 timeout-minutes : 60
3939 steps :
4040 - name : kics
4545
4646 iac-misconfig-detection-pulumi :
4747 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-pulumi' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
48- runs-on : ubuntu-22 .04
48+ runs-on : ubuntu-24 .04
4949 timeout-minutes : 60
5050 steps :
5151 - name : kics
5656
5757 iac-misconfig-detection-terraform :
5858 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'iac-misconfig-detection-terraform' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-iac-misconfiguration-detection'
59- runs-on : ubuntu-22 .04
59+ runs-on : ubuntu-24 .04
6060 timeout-minutes : 60
6161 steps :
6262 - name : kics
6767
6868 remediation-pr :
6969 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'remediation-pr' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-remediation-pr'
70- runs-on : ubuntu-22 .04
70+ runs-on : ubuntu-24 .04
7171 timeout-minutes : 60
7272 steps :
7373 - name : remediation-pr
7878
7979 secret-detection :
8080 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'secret-detection' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-secret-detection'
81- runs-on : ubuntu-22 .04
81+ runs-on : ubuntu-24 .04
8282 timeout-minutes : 60
8383 steps :
8484 - name : gitleaks
8989
9090 software-component-analysis-go :
9191 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'software-component-analysis-go' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sca'
92- runs-on : ubuntu-22 .04
92+ runs-on : ubuntu-24 .04
9393 timeout-minutes : 60
9494 steps :
9595 - name : nancy
9999
100100 software-component-analysis-js :
101101 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'software-component-analysis-js' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sca'
102- runs-on : ubuntu-22 .04
102+ runs-on : ubuntu-24 .04
103103 timeout-minutes : 60
104104 steps :
105105 - name : npm-audit
@@ -110,7 +110,7 @@ jobs:
110110
111111 software-component-analysis-php :
112112 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'software-component-analysis-php' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sca'
113- runs-on : ubuntu-22 .04
113+ runs-on : ubuntu-24 .04
114114 timeout-minutes : 60
115115 steps :
116116 - name : osv-scanner
@@ -121,7 +121,7 @@ jobs:
121121
122122 software-component-analysis-python :
123123 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'software-component-analysis-python' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sca'
124- runs-on : ubuntu-22 .04
124+ runs-on : ubuntu-24 .04
125125 timeout-minutes : 60
126126 steps :
127127 - name : osv-scanner
@@ -132,7 +132,7 @@ jobs:
132132
133133 static-code-analysis-c-cpp :
134134 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-c-cpp' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
135- runs-on : ubuntu-22 .04
135+ runs-on : ubuntu-24 .04
136136 timeout-minutes : 60
137137 steps :
138138 - name : semgrep
@@ -142,7 +142,7 @@ jobs:
142142
143143 static-code-analysis-csharp :
144144 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-csharp' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
145- runs-on : ubuntu-22 .04
145+ runs-on : ubuntu-24 .04
146146 timeout-minutes : 60
147147 steps :
148148 - name : semgrep
@@ -152,7 +152,7 @@ jobs:
152152
153153 static-code-analysis-go :
154154 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-go' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
155- runs-on : ubuntu-22 .04
155+ runs-on : ubuntu-24 .04
156156 timeout-minutes : 60
157157 steps :
158158 - name : gosec
@@ -162,7 +162,7 @@ jobs:
162162
163163 static-code-analysis-java :
164164 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-java' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
165- runs-on : ubuntu-22 .04
165+ runs-on : ubuntu-24 .04
166166 timeout-minutes : 60
167167 steps :
168168 - name : semgrep
@@ -172,7 +172,7 @@ jobs:
172172
173173 static-code-analysis-js :
174174 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-js' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
175- runs-on : ubuntu-22 .04
175+ runs-on : ubuntu-24 .04
176176 timeout-minutes : 60
177177 steps :
178178 - name : semgrep
@@ -182,7 +182,7 @@ jobs:
182182
183183 static-code-analysis-kotlin :
184184 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-kotlin' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
185- runs-on : ubuntu-22 .04
185+ runs-on : ubuntu-24 .04
186186 timeout-minutes : 60
187187 steps :
188188 - name : semgrep
@@ -192,7 +192,7 @@ jobs:
192192
193193 static-code-analysis-php :
194194 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-php' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
195- runs-on : ubuntu-22 .04
195+ runs-on : ubuntu-24 .04
196196 timeout-minutes : 60
197197 steps :
198198 - name : semgrep
@@ -202,7 +202,7 @@ jobs:
202202
203203 static-code-analysis-python-semgrep :
204204 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-python-semgrep' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
205- runs-on : ubuntu-22 .04
205+ runs-on : ubuntu-24 .04
206206 timeout-minutes : 60
207207 steps :
208208 - name : semgrep
@@ -212,7 +212,7 @@ jobs:
212212
213213 static-code-analysis-ruby :
214214 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-ruby' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
215- runs-on : ubuntu-22 .04
215+ runs-on : ubuntu-24 .04
216216 timeout-minutes : 60
217217 steps :
218218 - name : semgrep
@@ -222,7 +222,7 @@ jobs:
222222
223223 static-code-analysis-rust :
224224 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-rust' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
225- runs-on : ubuntu-22 .04
225+ runs-on : ubuntu-24 .04
226226 timeout-minutes : 60
227227 steps :
228228 - name : semgrep
@@ -232,7 +232,7 @@ jobs:
232232
233233 static-code-analysis-scala :
234234 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-scala' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
235- runs-on : ubuntu-22 .04
235+ runs-on : ubuntu-24 .04
236236 timeout-minutes : 60
237237 steps :
238238 - name : semgrep
@@ -242,7 +242,7 @@ jobs:
242242
243243 static-code-analysis-swift :
244244 if : fromJSON(github.event.inputs.client_payload).payload.workflow_job_name == 'static-code-analysis-swift' && fromJSON(github.event.inputs.client_payload).payload.workflow_slug == 'workflow-sast'
245- runs-on : ubuntu-22 .04
245+ runs-on : ubuntu-24 .04
246246 timeout-minutes : 60
247247 steps :
248248 - name : semgrep
0 commit comments