Skip to content

Bump rails from 7.1.4 to 7.1.4.2 #968

Bump rails from 7.1.4 to 7.1.4.2

Bump rails from 7.1.4 to 7.1.4.2 #968

Workflow file for this run

# Copyright 2023-2024, Pablo Fernandez
#
# This file is part of Repeater World.
#
# Repeater World is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General
# Public License as published by the Free Software Foundation, either version 3 of the License.
#
# Repeater World is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more
# details.
#
# You should have received a copy of the GNU Affero General Public License along with Repeater World. If not, see
# <https://www.gnu.org/licenses/>.
name: Push
on: push
jobs:
brakeman:
name: "Brakeman"
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Install Ruby and gems
uses: ruby/setup-ruby@v1
with:
bundler-cache: true
- name: Security audit application code
run: bundle exec brakeman --confidence-level 2 --format sarif --output sarif.json
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: sarif.json
# TODO: do we want this when we have dependabot?
# - name: Security audit dependencies
# run: bin/bundler-audit --update