From b04bf85b0b5305897a7fc9f260466d7bda60001a Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:02:39 -0300 Subject: [PATCH 01/14] Update sonarqube file --- .github/workflows/sonarqubescan.yml | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index bdeea537..2fa0e395 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -1,20 +1,18 @@ name: Run SonarQube with Maven - on: push - jobs: build: runs-on: ubuntu-latest - steps: + steps:git - uses: actions/checkout@v3 - name: Set up JDK 17 uses: actions/setup-java@v3 with: java-version: '17' - distribution: 'adopt' + distribution: 'temurin' cache: maven - name: Build with Maven cloud - run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachability -Dsonar.organization=javaprojectreachability -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN + run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabiliti -Dsonar.organization=javaprojectreachabiliti -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} \ No newline at end of file From 2faf720be3ace83be642a8b1d331ec0640acd328 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:34:58 -0300 Subject: [PATCH 02/14] distriburion adopt --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 2fa0e395..7702a0b9 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -9,7 +9,7 @@ jobs: uses: actions/setup-java@v3 with: java-version: '17' - distribution: 'temurin' + distribution: 'adopt' cache: maven - name: Build with Maven cloud run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabiliti -Dsonar.organization=javaprojectreachabiliti -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN From 2ba9f8d72382158241743e06cbade441d238fe75 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:38:53 -0300 Subject: [PATCH 03/14] distriburion temurin --- .github/{workflows => }/complete-workflow.yml | 0 .github/{workflows => }/owasp-zap-scan.yml | 0 .github/workflows/sonarqubescan.yml | 4 ++-- 3 files changed, 2 insertions(+), 2 deletions(-) rename .github/{workflows => }/complete-workflow.yml (100%) rename .github/{workflows => }/owasp-zap-scan.yml (100%) diff --git a/.github/workflows/complete-workflow.yml b/.github/complete-workflow.yml similarity index 100% rename from .github/workflows/complete-workflow.yml rename to .github/complete-workflow.yml diff --git a/.github/workflows/owasp-zap-scan.yml b/.github/owasp-zap-scan.yml similarity index 100% rename from .github/workflows/owasp-zap-scan.yml rename to .github/owasp-zap-scan.yml diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 7702a0b9..89e5eba8 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -4,12 +4,12 @@ jobs: build: runs-on: ubuntu-latest steps:git - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v3 with: java-version: '17' - distribution: 'adopt' + distribution: 'temurin' cache: maven - name: Build with Maven cloud run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabiliti -Dsonar.organization=javaprojectreachabiliti -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN From a3aed93cba37b66e9db5dcde45aaf3acb789dd1b Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:41:28 -0300 Subject: [PATCH 04/14] update sonar file --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 89e5eba8..7eef1523 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -3,7 +3,7 @@ on: push jobs: build: runs-on: ubuntu-latest - steps:git + steps: - uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v3 From c314149b7907d3cf895a4745bcdfacc7dbedcf94 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:49:15 -0300 Subject: [PATCH 05/14] main branch --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 7eef1523..d5eeaa46 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -9,7 +9,7 @@ jobs: uses: actions/setup-java@v3 with: java-version: '17' - distribution: 'temurin' + distribution: 'adopt' cache: maven - name: Build with Maven cloud run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabiliti -Dsonar.organization=javaprojectreachabiliti -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN From 85ed20371934415bec2286a347f05e12601d4c1e Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 11:53:58 -0300 Subject: [PATCH 06/14] organization ingwsee --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index d5eeaa46..c090c80d 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -12,7 +12,7 @@ jobs: distribution: 'adopt' cache: maven - name: Build with Maven cloud - run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabiliti -Dsonar.organization=javaprojectreachabiliti -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN + run: mvn -B verify sonar:sonar -Dsonar.projectKey=ingwsee -Dsonar.organization=ingwsee -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} \ No newline at end of file From e55c14bf43acb080e377068c6289fe170f8b9611 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 12:01:41 -0300 Subject: [PATCH 07/14] reachabilityyy --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index c090c80d..5e508ba9 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -12,7 +12,7 @@ jobs: distribution: 'adopt' cache: maven - name: Build with Maven cloud - run: mvn -B verify sonar:sonar -Dsonar.projectKey=ingwsee -Dsonar.organization=ingwsee -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN + run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabilityyy -Dsonar.organization=javaprojectreachabilityyy -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} \ No newline at end of file From 130073db64475220d1b1fa796172ee569eded7b5 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 12:14:13 -0300 Subject: [PATCH 08/14] sonar project javaprojectre --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 5e508ba9..f1349e20 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -12,7 +12,7 @@ jobs: distribution: 'adopt' cache: maven - name: Build with Maven cloud - run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectreachabilityyy -Dsonar.organization=javaprojectreachabilityyy -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN + run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectre -Dsonar.organization=javaprojectre -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} \ No newline at end of file From 2c18ecc4383d4417b806d870fddb41da30007199 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 14:06:16 -0300 Subject: [PATCH 09/14] setup java v4 --- .github/workflows/sonarqubescan.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index f1349e20..184c4b7f 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -6,10 +6,10 @@ jobs: steps: - uses: actions/checkout@v4 - name: Set up JDK 17 - uses: actions/setup-java@v3 + uses: actions/setup-java@v4 with: - java-version: '17' - distribution: 'adopt' + java-version: '21' + distribution: 'temurin' cache: maven - name: Build with Maven cloud run: mvn -B verify sonar:sonar -Dsonar.projectKey=javaprojectre -Dsonar.organization=javaprojectre -Dsonar.host.url=https://sonarcloud.io -Dsonar.token=$SONAR_TOKEN From 4c1cb1d10b0761979ab28dd32c4f0e6262f6a163 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 15:22:35 -0300 Subject: [PATCH 10/14] checkout v2 --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index 184c4b7f..af2809e0 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -4,7 +4,7 @@ jobs: build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v2 - name: Set up JDK 17 uses: actions/setup-java@v4 with: From 59ecdb7a7a4102686966fadc0c864bf7b762d95c Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 15:35:15 -0300 Subject: [PATCH 11/14] checkout v4 --- .github/workflows/sonarqubescan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sonarqubescan.yml b/.github/workflows/sonarqubescan.yml index af2809e0..184c4b7f 100644 --- a/.github/workflows/sonarqubescan.yml +++ b/.github/workflows/sonarqubescan.yml @@ -4,7 +4,7 @@ jobs: build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 - name: Set up JDK 17 uses: actions/setup-java@v4 with: From 1bb69665f0d2b9925a0022d5e12ac57b6b106bbc Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 15:43:43 -0300 Subject: [PATCH 12/14] update zap docker name --- .github/workflows/owasp-zap-scan.yml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 .github/workflows/owasp-zap-scan.yml diff --git a/.github/workflows/owasp-zap-scan.yml b/.github/workflows/owasp-zap-scan.yml new file mode 100644 index 00000000..4a5ed074 --- /dev/null +++ b/.github/workflows/owasp-zap-scan.yml @@ -0,0 +1,20 @@ +name: OWASP ZAP Integration with GitHub Actions + +on: [push] + +jobs: + zap_scan: + runs-on: ubuntu-latest + name: Scan the web application + steps: + - name: Checkout + uses: actions/checkout@v4 + with: + ref: main + - name: ZAP Scan + uses: zaproxy/action-baseline@v0.10.0 + with: + docker_name: 'ghcr.io/zaproxy/zaproxy:stable' + target: 'http://testphp.vulnweb.com/' + rules_file_name: '.zap/rules.tsv' + cmd_options: '-a' From c74b6f68dfc12645862541b332149ee260a1b03b Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 16:23:01 -0300 Subject: [PATCH 13/14] tsting zap2 --- .github/owasp-zap-scan.yml | 20 -------------------- 1 file changed, 20 deletions(-) delete mode 100644 .github/owasp-zap-scan.yml diff --git a/.github/owasp-zap-scan.yml b/.github/owasp-zap-scan.yml deleted file mode 100644 index 148af3ba..00000000 --- a/.github/owasp-zap-scan.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: OWASP ZAP Integration with GitHub Actions - -on: [push] - -jobs: - zap_scan: - runs-on: ubuntu-latest - name: Scan the web application - steps: - - name: Checkout - uses: actions/checkout@v2 - with: - ref: master - - name: ZAP Scan - uses: zaproxy/action-baseline@v0.6.1 - with: - docker_name: 'owasp/zap2docker-stable' - target: 'http://testphp.vulnweb.com/' - rules_file_name: '.zap/rules.tsv' - cmd_options: '-a' From 93422fdb79cf5a43ea4dadb1e6b372deeeb95b75 Mon Sep 17 00:00:00 2001 From: Santiago Encalada Date: Fri, 12 Jan 2024 16:32:13 -0300 Subject: [PATCH 14/14] enabling github issue repo - checkout v3 --- .github/workflows/owasp-zap-scan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/owasp-zap-scan.yml b/.github/workflows/owasp-zap-scan.yml index 4a5ed074..2cf13c64 100644 --- a/.github/workflows/owasp-zap-scan.yml +++ b/.github/workflows/owasp-zap-scan.yml @@ -8,7 +8,7 @@ jobs: name: Scan the web application steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v3 with: ref: main - name: ZAP Scan