Skip to content

Dependency Scanning

Dependency Scanning #2

Workflow file for this run

name: Dependency Scanning
on:
workflow_dispatch:
schedule:
- cron: '0 0 * * 0' # At 00:00 on Sunday
permissions:
contents: read # allow actions/checkout
jobs:
fossa:
name: Fossa
runs-on: ubuntu-22.04
if: github.event.repository.fork == false
steps:
- name: Checkout
# https://github.com/actions/checkout/releases
# v4.1.1
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
- name: Cache Coursier cache
# https://github.com/coursier/cache-action/releases
# v6.4.3
uses: coursier/cache-action@566e01fea33492e5a89706b43fb0d3fc884154f9
- name: Set up JDK 21
# https://github.com/coursier/setup-action/releases
# v1.3.5
uses: coursier/setup-action@7bde40eee928896f074dbb76d22dd772eed5c65f
with:
jvm: temurin:1.21
- name: FOSSA policy check
run: |-
curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install-latest.sh | bash
sbt "compile; makePom"
echo ### List targets ###
fossa list-targets
echo ### Akka SDK for Java ###
fossa analyze -p akka-javasdk \
--only-target scala@sdk/akka-javasdk/target/ \
--only-target scala@sdk/akka-javasdk-testkit/target/
echo ### report all parts including testkits, tests, TCKs, and samples ###
fossa analyze -p akka-javasdk-root
env:
FOSSA_API_KEY: "${{secrets.FOSSA_API_KEY}}"
FOSSA_TELEMETRY_SCOPE: off