| # This workflow uses actions that are not certified by GitHub. |
| # They are provided by a third-party and are governed by |
| # separate terms of service, privacy policy, and support |
| # documentation. |
| |
| # This workflow file requires a free account on Semgrep.dev to |
| # manage rules, file ignores, notifications, and more. |
| # |
| # See https://semgrep.dev/docs |
| |
| name: Semgrep |
| |
| on: |
| push: |
| branches: [ "develop" ] |
| pull_request: |
| # The branches below must be a subset of the branches above |
| branches: [ "develop" ] |
| schedule: |
| - cron: '23 2 * * 4' |
| |
| permissions: |
| contents: read |
| |
| jobs: |
| semgrep: |
| permissions: |
| contents: read # for actions/checkout to fetch code |
| security-events: write # for github/codeql-action/upload-sarif to upload SARIF results |
| actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status |
| name: Scan |
| runs-on: ubuntu-latest |
| steps: |
| - name: Harden Runner |
| uses: step-security/harden-runner@e3f713f2d8f53843e71c69a996d56f51aa9adfb9 # v2.14.1 |
| with: |
| egress-policy: audit |
| |
| # Checkout project source |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 |
| |
| # Scan code using project's configuration on https://semgrep.dev/manage |
| - uses: returntocorp/semgrep-action@713efdd345f3035192eaa63f56867b88e63e4e5d |
| with: |
| publishToken: ${{ secrets.SEMGREP_APP_TOKEN }} |
| publishDeployment: ${{ secrets.SEMGREP_DEPLOYMENT_ID }} |
| generateSarif: "1" |
| |
| # Upload SARIF file generated in previous step |
| - name: Upload SARIF file |
| uses: github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4 |
| with: |
| sarif_file: semgrep.sarif |
| if: always() |