diff --git a/.github/workflows/security-submit-dependecy-graph.yml b/.github/workflows/security-submit-dependecy-graph.yml new file mode 100644 index 0000000..e03d5a7 --- /dev/null +++ b/.github/workflows/security-submit-dependecy-graph.yml @@ -0,0 +1,23 @@ +name: Generate and submit dependency graph for wave-cli +on: + pull_request: + +permissions: + contents: write + +jobs: + dependency-submission: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-java@v4 + with: + distribution: temurin + java-version: 17 + + - name: Generate and submit dependency graph for wave-cli + uses: gradle/actions/dependency-submission@v4 + with: + dependency-resolution-task: "dependencies" + additional-arguments: "--configuration runtimeClasspath" + dependency-graph: generate-and-submit