@@ -32,14 +32,20 @@ blocks:
32
32
dependencies : []
33
33
run :
34
34
# don't run the tests on non-functional changes...
35
- when : " change_in('/', {exclude: ['/.deployed-versions/', '.github/']})"
35
+ when : " change_in('/', {exclude: ['/.deployed-versions/', '.github/'], default_branch: 'master' })"
36
36
task :
37
37
jobs :
38
38
- name : Test
39
39
commands :
40
40
- . sem-pint
41
41
- mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 --batch-mode --no-transfer-progress clean verify install dependency:analyze validate
42
- - cve-scan
42
+ - export TRIVY_DISABLE_VEX_NOTICE=true
43
+ - trivy version
44
+ - echo "Check go/connector-dev-vuln-remediation for fixing or suppressing vulnerabilities found by trivy"
45
+ - trivy --skip-files "*.zip" rootfs --scanners vuln --db-repository public.ecr.aws/aquasecurity/trivy-db --java-db-repository public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed
46
+ --ignorefile .trivyignore --exit-code 1 --severity CRITICAL target/components/packages
47
+ - trivy --skip-files "*.zip" rootfs --scanners vuln --db-repository public.ecr.aws/aquasecurity/trivy-db --java-db-repository public.ecr.aws/aquasecurity/trivy-java-db --ignore-unfixed
48
+ --ignorefile .trivyignore --severity HIGH,LOW,MEDIUM target/components/packages
43
49
- . cache-maven store
44
50
epilogue :
45
51
always :
@@ -56,14 +62,15 @@ blocks:
56
62
jobs :
57
63
- name : Release
58
64
commands :
59
- - mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 --batch-mode -DaltDeploymentRepository=confluent-codeartifact-internal::default::https://confluent-519856050701.d.codeartifact.us-west-2.amazonaws.com/maven/maven-snapshots/
65
+ - mvn -Dcloud -Pjenkins -U -Dmaven.wagon.http.retryHandler.count=10 --batch-mode
66
+ -DaltDeploymentRepository=confluent-codeartifact-internal::default::https://confluent-519856050701.d.codeartifact.us-west-2.amazonaws.com/maven/maven-snapshots/
60
67
-DrepositoryId=confluent-codeartifact-internal deploy -DskipTests
61
68
62
69
after_pipeline :
63
70
task :
64
71
agent :
65
72
machine :
66
- type : s1-prod-ubuntu24-04-arm64-0
73
+ type : s1-prod-ubuntu24-04-arm64-00
67
74
jobs :
68
75
- name : Metrics
69
76
commands :
0 commit comments