Skip to content

Commit

Permalink
ci: Add SARIF upload to GitHub Security Dashboard (#365)
Browse files Browse the repository at this point in the history
Co-authored-by: jkan2 <[email protected]>
  • Loading branch information
jkan2 and jkan2 authored Sep 27, 2024
1 parent 514eaac commit 60cadbb
Showing 1 changed file with 15 additions and 2 deletions.
17 changes: 15 additions & 2 deletions .github/workflows/semgrep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,21 @@ jobs:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
container:
image: semgrep/semgrep

if: (github.actor != 'dependabot[bot]')
steps:
- uses: actions/checkout@v4
- run: semgrep ci
- uses: actions/checkout@v4
- name: Checkout semgrep-utilities repo
uses: actions/checkout@v4
with:
repository: zeta-chain/semgrep-utilities
path: semgrep-utilities

- run: semgrep ci --json --output semgrep-findings.json

- run: python semgrep-utilities/utilities/github-sarif-helper/src/semgrep-json-to-sarif.py --json semgrep-findings.json --sarif semgrep-github.sarif

- name: Upload SARIF file for GitHub Advanced Security Dashboard
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: semgrep-github.sarif

0 comments on commit 60cadbb

Please sign in to comment.