generated from nhcarrigan/template
This commit is contained in:
@@ -58,20 +58,17 @@ jobs:
|
||||
cat trivy-results.txt
|
||||
fi
|
||||
|
||||
- name: Install Semgrep
|
||||
run: python3 -m pip install semgrep
|
||||
|
||||
# Static code analysis with Semgrep
|
||||
- name: Run Semgrep static analysis
|
||||
uses: returntocorp/semgrep-action@v1
|
||||
with:
|
||||
config: >-
|
||||
p/security-audit
|
||||
p/owasp-top-ten
|
||||
p/ci
|
||||
p/security
|
||||
generateSarif: '1'
|
||||
outputFormat: 'text'
|
||||
outputFile: 'semgrep-results.txt'
|
||||
# Fail on any finding
|
||||
error: 'true'
|
||||
run: |
|
||||
semgrep --config p/security-audit \
|
||||
--config p/owasp-top-ten \
|
||||
--config p/ci \
|
||||
--config p/security \
|
||||
. > semgrep-results.txt
|
||||
|
||||
# Display Semgrep results
|
||||
- name: Display Semgrep scan results
|
||||
|
||||
Reference in New Issue
Block a user