diff --git a/.github/workflows/code-quality.yml b/.github/workflows/code-quality.yml index 93a72ccb..7787d2e6 100644 --- a/.github/workflows/code-quality.yml +++ b/.github/workflows/code-quality.yml @@ -56,6 +56,14 @@ jobs: with: java-version: 11 distribution: 'temurin' + - name: Cache Maven packages + uses: actions/cache@v3 + with: + path: ~/.m2 + key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} + restore-keys: ${{ runner.os }}-m2 - name: Analyze dependencies + env: + NVD_API_KEY: ${{ secrets.NVD_TOKEN }} # this will run the OWASP dependency checker only run: mvn -B verify -DskipTests -Dgpg.skip diff --git a/pom.xml b/pom.xml index 4f1277b9..29d7cf0c 100644 --- a/pom.xml +++ b/pom.xml @@ -130,7 +130,7 @@ org.owasp dependency-check-maven - 8.4.3 + 9.0.7