Skip to content

build: use starflow #363

build: use starflow

build: use starflow #363

Workflow file for this run

name: Security scan
on:
pull_request:
push:
branches:
- main
- hotfix/*
- work/secscan # For development
jobs:
python-scans:
name: Scan Python project
# uses: canonical/starflow/.github/workflows/scan-python.yaml@main
uses: lengau/starflow/.github/workflows/scan-python.yaml@work/CRAFT-3707/uv

Check failure on line 14 in .github/workflows/security-scan.yaml

View workflow run for this annotation

GitHub Actions / Security scan

Invalid workflow file

The workflow is not valid. In .github/workflows/security-scan.yaml (Line: 14, Col: 11): Error from called workflow lengau/starflow/.github/workflows/scan-python.yaml@work/CRAFT-3707/uv (Line: 168, Col: 14): Unrecognized named-value: 'uv-sync-extra-args'. Located at position 1 within expression: uv-sync-extra-args
with:
packages: python-apt-dev
# 1. requirements-noble.txt can't build on jammy
# 2. Ignore requirements files in spread tests, as some of these intentionally
# contain vulnerable versions.
requirements-find-args: '! -name requirements-noble.txt ! -path "./tests/spread/*"'
osv-extra-args: '--config=source/osv-scanner.toml'
uv-export: false
uv-sync-extra-args: --no-dev