SQSCANGHA-140 Add OpenPGP signature verification for scanner downloads (#235)
Some checks are pending
QA Deprecated C and C++ action / Action outputs (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-1 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-2 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-3 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-4 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-5 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-6 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-7 (push) Waiting to run
QA Deprecated C and C++ action / Action outputs-8 (push) Waiting to run
QA Install Build Wrapper action / Action outputs (push) Waiting to run
QA Install Build Wrapper action / Action outputs-1 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-2 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-3 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-4 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-5 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-6 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-7 (push) Waiting to run
QA Install Build Wrapper action / Action outputs-8 (push) Waiting to run
QA Main action / No inputs (push) Waiting to run
QA Main action / No inputs -1 (push) Waiting to run
QA Main action / 'args' input (push) Waiting to run
QA Main action / 'args' input -1 (push) Waiting to run
QA Main action / 'args' input -2 (push) Waiting to run
QA Main action / 'args' input with other command injection variants does not execute command -2 (push) Waiting to run
QA Main action / 'projectBaseDir' input -2 (push) Waiting to run
QA Main action / 'scannerBinariesUrl' input with invalid URL (push) Waiting to run
QA Main action / 'RUNNER_DEBUG' is used (push) Waiting to run
QA Main action / 'RUNNER_DEBUG' is used -1 (push) Waiting to run
Unit tests / test (push) Waiting to run
QA Main action / 'args' input with command injection will fail (push) Waiting to run
QA Main action / 'args' input with command injection will fail -1 (push) Waiting to run
QA Main action / 'args' input with command injection will fail -2 (push) Waiting to run
QA Main action / 'args' input with command injection will fail -3 (push) Waiting to run
QA Main action / 'args' input with command injection will fail -4 (push) Waiting to run
QA Main action / 'args' input with command injection will fail -5 (push) Waiting to run
QA Main action / 'args' input with backticks injection does not execute command (push) Waiting to run
QA Main action / 'args' input with backticks injection does not execute command -1 (push) Waiting to run
QA Main action / 'args' input with backticks injection does not execute command -2 (push) Waiting to run
QA Main action / 'args' input with dollar command injection does not execute command (push) Waiting to run
QA Main action / 'args' input with dollar command injection does not execute command -1 (push) Waiting to run
QA Main action / 'args' input with dollar command injection does not execute command -2 (push) Waiting to run
QA Main action / 'args' input with other command injection variants does not execute command (push) Waiting to run
QA Main action / 'args' input with other command injection variants does not execute command -1 (push) Waiting to run
QA Main action / 'projectBaseDir' input (push) Waiting to run
QA Main action / 'projectBaseDir' input -1 (push) Waiting to run
QA Main action / 'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command (push) Waiting to run
QA Main action / 'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command (push) Waiting to run
QA Main action / Don't fail on Gradle project (push) Waiting to run
QA Main action / 'SONARCLOUD_URL' is used -1 (push) Waiting to run
QA Main action / 'SONAR_ROOT_CERT' is converted to truststore -2 (push) Waiting to run
QA Main action / truststore.p12 is updated when present (push) Waiting to run
QA Main action / 'scannerVersion' input validation (push) Waiting to run
QA Scripts / fetch_latest_version.sh (push) Waiting to run
QA Scripts / create_install_path.sh (push) Waiting to run
QA Main action / 'scannerVersion' input (push) Waiting to run
QA Main action / Don't fail on Kotlin Gradle project (push) Waiting to run
QA Main action / Don't fail on Maven project (push) Waiting to run
QA Main action / runAnalysisTest (push) Waiting to run
QA Main action / 'RUNNER_DEBUG' is used -2 (push) Waiting to run
QA Main action / runAnalysisWithCacheTest (push) Waiting to run
QA Main action / 'SONARCLOUD_URL' is used (push) Waiting to run
QA Main action / 'SONARCLOUD_URL' is used -2 (push) Waiting to run
QA Main action / curl performs redirect when scannerBinariesUrl returns 3xx (push) Waiting to run
QA Main action / 'SONAR_ROOT_CERT' is converted to truststore (push) Waiting to run
QA Main action / 'SONAR_ROOT_CERT' is converted to truststore -1 (push) Waiting to run
QA Main action / Analysis takes into account 'SONAR_ROOT_CERT' (push) Waiting to run
QA Scripts / configure_paths.sh (push) Waiting to run
QA Scripts / download.sh (push) Waiting to run

This commit is contained in:
Claire Villard 2026-04-28 15:49:48 +02:00 committed by GitHub
parent 30dbe5c9ee
commit 55e44800a8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
17 changed files with 33778 additions and 41 deletions

27
package-lock.json generated
View file

@ -10,6 +10,7 @@
"license": "LGPL-3.0-only",
"dependencies": {
"@actions/core": "3.0.0",
"@actions/exec": "2.0.0",
"@actions/github": "9.0.0",
"@actions/tool-cache": "4.0.0",
"string-argv": "0.3.2"
@ -31,7 +32,7 @@
"@actions/http-client": "^4.0.0"
}
},
"node_modules/@actions/exec": {
"node_modules/@actions/core/node_modules/@actions/exec": {
"version": "3.0.0",
"resolved": "https://repox.jfrog.io/artifactory/api/npm/npm/@actions/exec/-/exec-3.0.0.tgz",
"integrity": "sha512-6xH/puSoNBXb72VPlZVm7vQ+svQpFyA96qdDBvhB8eNZOE8LtPf9L4oAsfzK/crCL8YZ+19fKYVnM63Sl+Xzlw==",
@ -40,6 +41,21 @@
"@actions/io": "^3.0.2"
}
},
"node_modules/@actions/exec": {
"version": "2.0.0",
"resolved": "https://repox.jfrog.io/artifactory/api/npm/npm/@actions/exec/-/exec-2.0.0.tgz",
"integrity": "sha512-k8ngrX2voJ/RIN6r9xB82NVqKpnMRtxDoiO+g3olkIUpQNqjArXrCQceduQZCQj3P3xm32pChRLqRrtXTlqhIw==",
"license": "MIT",
"dependencies": {
"@actions/io": "^2.0.0"
}
},
"node_modules/@actions/exec/node_modules/@actions/io": {
"version": "2.0.0",
"resolved": "https://repox.jfrog.io/artifactory/api/npm/npm/@actions/io/-/io-2.0.0.tgz",
"integrity": "sha512-Jv33IN09XLO+0HS79aaODsvIRyduiF7NY/F6LYeK5oeUmrsz7aFdRphQjFoESF4jS7lMauDOttKALcpapVDIAg==",
"license": "MIT"
},
"node_modules/@actions/github": {
"version": "9.0.0",
"resolved": "https://repox.jfrog.io/artifactory/api/npm/npm/@actions/github/-/github-9.0.0.tgz",
@ -94,6 +110,15 @@
"semver": "^7.7.3"
}
},
"node_modules/@actions/tool-cache/node_modules/@actions/exec": {
"version": "3.0.0",
"resolved": "https://repox.jfrog.io/artifactory/api/npm/npm/@actions/exec/-/exec-3.0.0.tgz",
"integrity": "sha512-6xH/puSoNBXb72VPlZVm7vQ+svQpFyA96qdDBvhB8eNZOE8LtPf9L4oAsfzK/crCL8YZ+19fKYVnM63Sl+Xzlw==",
"license": "MIT",
"dependencies": {
"@actions/io": "^3.0.2"
}
},
"node_modules/@jridgewell/sourcemap-codec": {
"version": "1.5.5",
"resolved": "https://registry.npmjs.org/@jridgewell/sourcemap-codec/-/sourcemap-codec-1.5.5.tgz",