diff --git a/.github/workflows/dependabot-alerts-to-slack.yml b/.github/workflows/dependabot-alerts-to-slack.yml index bbe35da..0bea296 100644 --- a/.github/workflows/dependabot-alerts-to-slack.yml +++ b/.github/workflows/dependabot-alerts-to-slack.yml @@ -1,17 +1,23 @@ -name: 'Check for Dependabot alerts & send them to slack' +name: 'Check for Dependabot alerts & send them to Slack' on: schedule: - - cron: '0 8 * * *' # every day at 8 am + - cron: '30 16 * * *' # every day at 9:30 am PST workflow_dispatch: # to have the option to run this ad-hoc jobs: main: runs-on: ubuntu-latest steps: + - uses: actions/create-github-app-token@v1 + id: app-token + with: + app-id: ${{ vars.DEPENDABOT_ACCESS_APP_ID }} + private-key: ${{ secrets.DEPENDABOT_ACCESS_PRIVATE_KEY }} + # X.X.X - Latest version available at: https://github.com/kunalnagarco/action-cve/releases - uses: kunalnagarco/action-cve@v1.13.2 with: - token: ${{ secrets.DEPENDABOT_TOKEN }} - slack_webhook: ${{ secrets.SLACK_WEBHOOK }} + token: ${{ steps.app-token.outputs.token }} + slack_webhook: ${{ secrets.CUSTOMER_INTEGRATIONS_SLACK_WEBHOOK }} count: 10