diff --git a/.github/workflows/monthly-vulnerability-scan.yml b/.github/workflows/monthly-vulnerability-scan.yml index eea0819..1a90968 100644 --- a/.github/workflows/monthly-vulnerability-scan.yml +++ b/.github/workflows/monthly-vulnerability-scan.yml @@ -1,4 +1,3 @@ -# .github/workflows/monthly-vulnerability-scan.yml name: Monthly Vulnerability Scan on: @@ -24,4 +23,11 @@ jobs: run: dotnet restore - name: List vulnerable packages - run: dotnet list package --vulnerable + run: | + set -e + results=$(dotnet list package --vulnerable) + echo "$results" + if echo "$results" | grep -q "has the following vulnerable packages"; then + echo "Vulnerabilities found!" + exit 1 + fi