Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
# renovate: datasource=github-releases depName=python/cpython
PYTHON_VERSION: "3.13.5"
# renovate: datasource=github-releases depName=kubernetes/kubernetes
KUBECTL_VERSION: "v1.36.2"
KUBECTL_VERSION: "v1.36.3"
# renovate: datasource=github-releases depName=kubernetes-sigs/kind
KIND_BINARY_VERSION: "v0.32.0"
# renovate: datasource=github-releases depName=helm/helm
Expand All @@ -44,7 +44,7 @@

- name: Install dependencies
working-directory: tests/integration
run: bun install

Check warning on line 47 in .github/workflows/ci.yaml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=secureCodeBox_secureCodeBox&issues=AZ-MuZvQ485lOTQ5P5Ko&open=AZ-MuZvQ485lOTQ5P5Ko&pullRequest=3736

Check warning on line 47 in .github/workflows/ci.yaml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=secureCodeBox_secureCodeBox&issues=AZ-MuZvQ485lOTQ5P5Kn&open=AZ-MuZvQ485lOTQ5P5Kn&pullRequest=3736

- name: Test Node.js Scanner Test Helpers
working-directory: tests/integration
Expand All @@ -57,17 +57,17 @@

- name: Install Kind
run: |
curl -Lo ./kind https://kind.sigs.k8s.io/dl/${{ env.KIND_BINARY_VERSION }}/kind-linux-amd64

Check warning on line 60 in .github/workflows/ci.yaml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=secureCodeBox_secureCodeBox&issues=AZ-MuZvQ485lOTQ5P5Kp&open=AZ-MuZvQ485lOTQ5P5Kp&pullRequest=3736
chmod +x ./kind

- name: Install Kubectl
run: |
curl -Lo ./kubectl curl -LO https://dl.k8s.io/release/${{ env.KUBECTL_VERSION }}/bin/linux/amd64/kubectl

Check warning on line 65 in .github/workflows/ci.yaml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=secureCodeBox_secureCodeBox&issues=AZ-MuZvQ485lOTQ5P5Kq&open=AZ-MuZvQ485lOTQ5P5Kq&pullRequest=3736
chmod +x ./kubectl

- name: Install Helm
run: |
curl -Lo ./helm.tar.gz https://get.helm.sh/helm-${{ env.HELM_VERSION }}-linux-amd64.tar.gz

Check warning on line 70 in .github/workflows/ci.yaml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=secureCodeBox_secureCodeBox&issues=AZ-MuZvQ485lOTQ5P5Kr&open=AZ-MuZvQ485lOTQ5P5Kr&pullRequest=3736
tar -xzf ./helm.tar.gz
chmod +x ./linux-amd64/helm

Expand Down
Loading