I tried multiple ways to do this but none worked for me. In the end, I ended up with the following step:
script:
- gradle build -x check
- wget https://github.com/snyk/snyk/releases/download/v1.464.0/snyk-linux
- chmod +x snyk-linux
- ./snyk-linux auth $SNYK_TOKEN
- ./snyk-linux test -d --all-projects --json-file-output=snyk-test-output.json
- cat snyk-test-output.json
- pipe: snyk/snyk-scan:0.4.6
variables:
SNYK_TOKEN: $SNYK_TOKEN
SNYK_TEST_JSON_INPUT: "snyk-test-output.json"
This, however, results in an error:
===== DEBUG INFORMATION START =====
gradle command: '/opt/atlassian/pipelines/agent/build/gradlew' snykResolvedDepsJson -q --build-file build.gradle --no-daemon -Dorg.gradle.parallel= -Dorg.gradle.console=plain -I /tmp/tmp-202-8XBM7uGB0V1d--init.gradle
[COULD NOT RUN gradle -v]
>>> command: '/opt/atlassian/pipelines/agent/build/gradlew' snykResolvedDepsJson -q --build-file build.gradle --no-daemon -Dorg.gradle.parallel= -Dorg.gradle.console=plain -I /tmp/tmp-202-8XBM7uGB0V1d--init.gradle
>>> exit code: 126
>>> stdout:
>>> stderr:
/bin/sh: 1: /opt/atlassian/pipelines/agent/build/gradlew: Permission denied
===== DEBUG INFORMATION END =====
When I run the same sequence of commands, all works fine:
- ./snyk-linux auth $SNYK_TOKEN
- ./snyk-linux test -d --all-projects --json-file-output=snyk-test-output.json
This is the link to my project: https://bitbucket.org/ig0rski/spring-boot-example/src/master/