Skip to content

Commit

Permalink
Use OSS Index API to avoid API rate limit
Browse files Browse the repository at this point in the history
Signed-off-by: Victor Chang <[email protected]>
  • Loading branch information
mocsharp committed Jun 23, 2022
1 parent cf0e47f commit bdc23e9
Show file tree
Hide file tree
Showing 2 changed files with 43 additions and 34 deletions.
5 changes: 4 additions & 1 deletion .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,4 +50,7 @@ jobs:
working-directory: ./src

- name: Dependency Scanning
run: nugetdefense -p src/Monai.Deploy.WorkflowManager.sln --settings-file NuGetDefense.json
run: |
sed -i "s/OSSINDEXAPI_TOKEN/$OSSINDEXAPI_TOKEN/g" NuGetDefense.json
sed -i "s/OSSINDEXAPI_USERNAME/$OSSINDEXAPI_USERNAME/g" NuGetDefense.json
nugetdefense -p src/Monai.Deploy.WorkflowManager.sln --settings-file NuGetDefense.json
72 changes: 39 additions & 33 deletions NuGetDefense.json
Original file line number Diff line number Diff line change
@@ -1,35 +1,41 @@
{
"WarnOnly": false,
"VulnerabilityReports": {
"OutputTextReport": true
},
"CheckTransitiveDependencies": true,
"CheckReferencedProjects": false,
"ErrorSettings": {
"ErrorSeverityThreshold": "any",
"Cvss3Threshold": -1,
"IgnoredPackages": [
{
"Id": "NugetDefense"
}
],
"IgnoredCvEs": [],
"AllowedPackages": [],
"WhiteListedPackages": [],
"BlockedPackages": [],
"BlacklistedPackages": []
},
"GitHubAdvisoryDatabase": {
"ApiToken": "",
"Username": "",
"Enabled": false,
"BreakIfCannotRun": false
},
"NVD": {
"SelfUpdate": false,
"TimeoutInSeconds": 30,
"Enabled": false,
"BreakIfCannotRun": false
},
"SensitivePackages": []
"WarnOnly": false,
"VulnerabilityReports": {
"OutputTextReport": true
},
"CheckTransitiveDependencies": true,
"CheckReferencedProjects": false,
"ErrorSettings": {
"ErrorSeverityThreshold": "any",
"Cvss3Threshold": -1,
"IgnoredPackages": [
{
"Id": "NugetDefense"
}
],
"IgnoredCvEs": [],
"AllowedPackages": [],
"WhiteListedPackages": [],
"BlockedPackages": [],
"BlacklistedPackages": []
},
"OssIndex": {
"ApiToken": "OSSINDEXAPI_TOKEN",
"Username": "OSSINDEXAPI_USERNAME",
"Enabled": true,
"BreakIfCannotRun": false
},
"GitHubAdvisoryDatabase": {
"ApiToken": "",
"Username": "",
"Enabled": false,
"BreakIfCannotRun": false
},
"NVD": {
"SelfUpdate": false,
"TimeoutInSeconds": 30,
"Enabled": false,
"BreakIfCannotRun": false
},
"SensitivePackages": []
}

0 comments on commit bdc23e9

Please sign in to comment.