diff --git a/.github/workflows/owasp.yml b/.github/workflows/owasp.yml index d168ef811..5f2578351 100644 --- a/.github/workflows/owasp.yml +++ b/.github/workflows/owasp.yml @@ -33,8 +33,9 @@ jobs: - name: Generate DependencyCheck report run: ./gradlew dependencyCheckAggregate + env: + ORG_GRADLE_PROJECT_OWASP_API_KEY: ${{ secrets.ORG_GRADLE_PROJECT_OWASP_API_KEY }} - name: upload-sarif-4 uses: github/codeql-action/upload-sarif@v2 with: sarif_file: ./build/reports/owasp-dependency-check/dependency-check-report.sarif - diff --git a/build.gradle b/build.gradle index 2002e06ae..e6b33f213 100644 --- a/build.gradle +++ b/build.gradle @@ -201,6 +201,7 @@ allprojects { dependencyCheck { outputDirectory = "$buildDir/reports/owasp-dependency-check" formats = [ReportGenerator.Format.SARIF.toString()] + nvd.apiKey = project.findProperty("OWASP_API_KEY") } def static readEnvFile(path = ".env") {