Add files via upload

Signed-off-by: nirpel-sys <nirpel@jfrog.com>
This commit is contained in:
nirpel-sys 2026-01-30 15:49:52 +02:00 committed by GitHub
parent d99129a9c8
commit dd9b2f6ac3
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -0,0 +1,30 @@
name: "Frogbot Scan Pull Request"
on:
pull_request_target:
types: [opened, synchronize]
permissions:
pull-requests: write
contents: read
id-token: write
jobs:
scan-pull-request:
runs-on: ubuntu-latest
steps:
- uses: jfrog/frogbot@v2
env:
# [Mandatory]
JF_URL: ${{ secrets.JF_URL }}
# [Mandatory]
JF_GIT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# [Optional] Xray Watches to apply
JF_WATCHES: "build-watch"
# [Optional] Show all vulnerabilities, not just the ones introduced in the PR
JF_INCLUDE_ALL_VULNERABILITIES: "true"
# [Mandatory if using OIDC authentication protocol instead of JF_ACCESS_TOKEN]
with:
oidc-provider-name: yanirw/CI-demo@github