blob: f4b7be10f4c0dd689e3e409af725c73141112b53 [file]
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
# Submits the resolved sbt dependency graph (all modules, transitive
# dependencies included) to GitHub via the Dependency Submission API so
# that Dependabot alerts cover Scala dependencies, which GitHub cannot
# parse from build.sbt on its own.
name: Update Dependency Graph
on:
push:
branches:
- main
permissions: {}
jobs:
dependency-graph:
name: Update Dependency Graph
runs-on: ubuntu-latest
if: github.repository == 'apache/texera'
permissions:
# The Dependency Submission API requires write permission
# on the repository
contents: write
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: Setup JDK
uses: actions/setup-java@v5
with:
distribution: 'temurin'
java-version: 17
- name: Setup sbt launcher
uses: sbt/setup-sbt@6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2
- uses: coursier/cache-action@95e5b1029b6b86e7bac033ee44a0697d8a527d2d # v8.1.1
- name: Submit sbt dependency graph
uses: scalacenter/sbt-dependency-submission@d84eef4c09e633bcf5f113bcad7fd5e9af1baee9 # v3.2.3
with:
configs-ignore: provided optional test compile-internal runtime-internal scala-tool scala-doc-tool