2021-09-10 12:11:35 +00:00
|
|
|
name: ✍🏻 CVE Annotate
|
|
|
|
|
|
|
|
on:
|
|
|
|
pull_request:
|
|
|
|
branches:
|
|
|
|
- master
|
|
|
|
workflow_dispatch:
|
|
|
|
|
|
|
|
jobs:
|
|
|
|
docs:
|
|
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
|
|
- uses: actions/checkout@master
|
|
|
|
with:
|
|
|
|
persist-credentials: false
|
|
|
|
fetch-depth: 0
|
|
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
2021-09-10 12:18:49 +00:00
|
|
|
|
2021-09-10 12:11:35 +00:00
|
|
|
- uses: actions/setup-go@v2
|
2021-09-10 12:18:49 +00:00
|
|
|
with:
|
2021-09-10 12:11:35 +00:00
|
|
|
go-version: 1.17
|
|
|
|
|
|
|
|
- name: Generate CVE Annotations
|
|
|
|
id: cve-annotate
|
|
|
|
run: |
|
|
|
|
if ! which cve-annotate > /dev/null; then
|
|
|
|
echo -e "Command cve-annotate not found! Installing\c"
|
2021-09-10 17:21:07 +00:00
|
|
|
go install github.com/projectdiscovery/nuclei/v2/cmd/cve-annotate@master
|
2021-09-10 12:11:35 +00:00
|
|
|
fi
|
|
|
|
cve-annotate -i ./cves/ -d .
|
|
|
|
echo "::set-output name=changes::$(git status -s | wc -l)"
|
|
|
|
|
|
|
|
- name: Commit files
|
|
|
|
if: steps.cve-annotate.outputs.changes > 0
|
|
|
|
run: |
|
|
|
|
git config --local user.email "action@github.com"
|
|
|
|
git config --local user.name "GitHub Action"
|
|
|
|
git add cves
|
|
|
|
git commit -m "Auto Generated CVE annotations [$(date)] :robot:" -a
|
|
|
|
|
|
|
|
- name: Push changes
|
|
|
|
if: steps.cve-annotate.outputs.changes > 0
|
|
|
|
uses: ad-m/github-push-action@master
|
|
|
|
with:
|
|
|
|
github_token: ${{ secrets.GITHUB_TOKEN }}
|
2021-09-10 17:41:34 +00:00
|
|
|
branch: ${{ github.ref }}
|