GODT-1853: ignore for CVE-2021-33194 false positive + add several try to gobinsec

This commit is contained in:
Romain LE JEUNE 2022-09-22 17:08:07 +02:00
parent 1cc7ea5ca7
commit a635b023f6
No known key found for this signature in database
GPG Key ID: 664A57E2F9CD8118
3 changed files with 10 additions and 1 deletions

View File

@ -270,7 +270,7 @@ check-gobinsec:
- cp ./gobinsec-cache-valid.yml ./gobinsec-cache.yml
script:
- cat ./gobinsec-cache.yml
- gobinsec -wait -cache -config utils/gobinsec_conf.yml build/bridge
- ./utils/run_gobinsec.sh
- cp ./gobinsec-cache.yml ./gobinsec-cache-valid.yml # Only update cache file if gobinsec succeeds

View File

@ -5,3 +5,7 @@ wait: true
file:
name: "./gobinsec-cache.yml"
expiration: 24h
ignore:
# golang.org/x/net wrong match, we are using 2871e0cb, fixed by 37e1c6af
- "CVE-2021-33194"

5
utils/run_gobinsec.sh Executable file
View File

@ -0,0 +1,5 @@
#!/bin/bash
gobinsec -wait -cache -config utils/gobinsec_conf.yml build/bridge || FAILED=true
if [ $FAILED ]; then
gobinsec -wait -cache -config utils/gobinsec_conf.yml build/bridge
fi