fix: use pip-audit exit code for vulnerability check
This commit is contained in:
parent
bc82574fb0
commit
7def4e3abb
@ -112,12 +112,14 @@ jobs:
|
|||||||
UV_NO_PROGRESS: "1"
|
UV_NO_PROGRESS: "1"
|
||||||
run: |
|
run: |
|
||||||
uv pip compile pyproject.toml --no-deps -o requirements-prod.txt
|
uv pip compile pyproject.toml --no-deps -o requirements-prod.txt
|
||||||
uv run pip-audit --format json --output audit-results.json -r requirements-prod.txt || true
|
# pip-audit returns exit code 1 if vulnerabilities found, 0 if none
|
||||||
if [ -s audit-results.json ] && [ "$(cat audit-results.json)" != "[]" ]; then
|
if uv run pip-audit --format json --output audit-results.json -r requirements-prod.txt; then
|
||||||
echo "❌ Found vulnerabilities"
|
echo "✅ No vulnerabilities found"
|
||||||
|
rm -f audit-results.json
|
||||||
|
else
|
||||||
|
echo "❌ Found vulnerabilities - see security-audit artifact"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "✅ No vulnerabilities found"
|
|
||||||
|
|
||||||
- name: Upload audit log
|
- name: Upload audit log
|
||||||
uses: actions/upload-artifact@v3
|
uses: actions/upload-artifact@v3
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user