diff --git a/.github/actions/rl-scanner/action.yml b/.github/actions/rl-scanner/action.yml index 96e9d3a3..98db8de8 100644 --- a/.github/actions/rl-scanner/action.yml +++ b/.github/actions/rl-scanner/action.yml @@ -31,16 +31,23 @@ runs: pip install --upgrade pip pip install boto3 requests + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v1 + with: + role-to-assume: ${{ env.PRODSEC_TOOLS_ARN }} + aws-region: us-east-1 + mask-aws-account-id: true + - name: Install RL Wrapper shell: bash run: | - pip install rl-wrapper>=1.0.0 --index-url "https://${{ env.PROD_TOOLS_USER }}:${{ env.PROD_TOOLS_TOKEN }}@a0us.jfrog.io/artifactory/api/pypi/python-local/simple" + pip install rl-wrapper>=1.0.0 --index-url "https://${{ env.PRODSEC_TOOLS_USER }}:${{ env.PRODSEC_TOOLS_TOKEN }}@a0us.jfrog.io/artifactory/api/pypi/python-local/simple" - name: Run RL Scanner shell: bash env: - RLSECURE_LICENSE: ${{ env.RL_SECURE_LICENSE }} - RLSECURE_SITE_KEY: ${{ env.RL_SECURE_SITE_KEY }} + RLSECURE_LICENSE: ${{ env.RLSECURE_LICENSE }} + RLSECURE_SITE_KEY: ${{ env.RLSECURE_SITE_KEY }} SIGNAL_HANDLER_TOKEN: ${{ env.SIGNAL_HANDLER_TOKEN }} PYTHONUNBUFFERED: 1 run: | diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 69bd809f..81008f9e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -23,13 +23,14 @@ jobs: node-version: 18 artifact-name: 'auth0-react.tgz' secrets: - RL_SECURE_LICENSE: ${{ secrets.RLSECURE_LICENSE }} - RL_SECURE_SITE_KEY: ${{ secrets.RLSECURE_SITE_KEY }} + RLSECURE_LICENSE: ${{ secrets.RLSECURE_LICENSE }} + RLSECURE_SITE_KEY: ${{ secrets.RLSECURE_SITE_KEY }} SIGNAL_HANDLER_TOKEN: ${{ secrets.SIGNAL_HANDLER_TOKEN }} - PROD_TOOLS_USER: ${{ secrets.PRODSEC_TOOLS_USER }} - PROD_TOOLS_TOKEN: ${{ secrets.PRODSEC_TOOLS_TOKEN }} + PRODSEC_TOOLS_USER: ${{ secrets.PRODSEC_TOOLS_USER }} + PRODSEC_TOOLS_TOKEN: ${{ secrets.PRODSEC_TOOLS_TOKEN }} release: uses: ./.github/workflows/npm-release.yml + needs: rl-scanner with: node-version: 18 require-build: true diff --git a/.github/workflows/rl-secure.yml b/.github/workflows/rl-secure.yml index 0cd37d8c..23816696 100644 --- a/.github/workflows/rl-secure.yml +++ b/.github/workflows/rl-secure.yml @@ -10,15 +10,15 @@ on: required: true type: string secrets: - RL_SECURE_LICENSE: + RLSECURE_LICENSE: required: true - RL_SECURE_SITE_KEY: + RLSECURE_SITE_KEY: required: true SIGNAL_HANDLER_TOKEN: required: true - PROD_TOOLS_USER: + PRODSEC_TOOLS_USER: required: true - PROD_TOOLS_TOKEN: + PRODSEC_TOOLS_TOKEN: required: true jobs: @@ -55,11 +55,11 @@ jobs: repository: "${{ github.repository }}" commit: "${{ github.sha }}" env: - RL_SECURE_LICENSE: ${{ secrets.RL_SECURE_LICENSE }} - RL_SECURE_SITE_KEY: ${{ secrets.RL_SECURE_SITE_KEY }} + RLSECURE_LICENSE: ${{ secrets.RLSECURE_LICENSE }} + RLSECURE_SITE_KEY: ${{ secrets.RLSECURE_SITE_KEY }} SIGNAL_HANDLER_TOKEN: ${{ secrets.SIGNAL_HANDLER_TOKEN }} - PROD_TOOLS_USER: ${{ secrets.PROD_TOOLS_USER }} - PROD_TOOLS_TOKEN: ${{ secrets.PROD_TOOLS_TOKEN }} + PRODSEC_TOOLS_USER: ${{ secrets.PRODSEC_TOOLS_USER }} + PRODSEC_TOOLS_TOKEN: ${{ secrets.PRODSEC_TOOLS_TOKEN }} - name: Output scan result run: echo "scan-status=${{ steps.rl-scan-conclusion.outcome }}" >> $GITHUB_ENV