diff --git a/.github/workflows/owasp.yml b/.github/workflows/owasp.yml index 238b77a4a..8625e3162 100644 --- a/.github/workflows/owasp.yml +++ b/.github/workflows/owasp.yml @@ -17,10 +17,16 @@ jobs: - name: Checkout repository uses: actions/checkout@v4 - - run: | + - env: + NVD_API_KEY: + ${{ secrets.NVD_API_KEY }} + run: | mvn -DskipTests install -P OWASP_CHECK - - run: | + - env: + NVD_API_KEY: + ${{ secrets.NVD_API_KEY }} + run: | mvn -DskipTests dependency-check:aggregate -P OWASP_CHECK - name: Upload SARIF file diff --git a/pom.xml b/pom.xml index 0af1a743c..8de072975 100644 --- a/pom.xml +++ b/pom.xml @@ -384,8 +384,9 @@ org.owasp dependency-check-maven - 8.2.1 + 11.1.1 + NVD_API_KEY cve-suppression.xml