diff --git a/.github/workflows/snyk.yml b/.github/workflows/snyk.yml index 872d3309..4e796d25 100644 --- a/.github/workflows/snyk.yml +++ b/.github/workflows/snyk.yml @@ -7,14 +7,11 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@master - - name: Run Snyk to check for vulnerabilities - uses: snyk/actions/golang@master - continue-on-error: true # To make sure that SARIF upload gets called - env: - SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} - with: - args: --sarif-file-output=snyk.sarif - - name: Upload result to GitHub Code Scanning - uses: github/codeql-action/upload-sarif@v2 + - uses: snyk/actions/setup@master + - uses: actions/setup-go@v1 with: - sarif_file: snyk.sarif \ No newline at end of file + go-version: '1.20' + - name: Snyk monitor + run: snyk code test + env: + SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }} \ No newline at end of file diff --git a/docker/build.Dockerfile b/docker/build.Dockerfile index ee1cfa22..1c9a48b5 100644 --- a/docker/build.Dockerfile +++ b/docker/build.Dockerfile @@ -24,11 +24,11 @@ COPY --from=build-env /go/bin/cosmovisor /usr/bin/cosmovisor COPY --from=build-env /go/src/github.com/haqq-network/haqq/build/haqqd /usr/bin/haqqd RUN apk add --no-cache \ - ca-certificates=20230506-r0 jq=~1.6 \ - curl=~8.4 bash=~5.2 \ - vim=~9.0 lz4=~1.9 \ - tini=~0.19 \ - gcompat=~1.1 + ca-certificates jq \ + curl bash \ + vim lz4 \ + tini \ + gcompat RUN addgroup -g 1000 haqq \ && adduser -S -h /home/haqq -D haqq -u 1000 -G haqq