diff --git a/.gitea/workflows/security.yml b/.gitea/workflows/security.yml index d16b369..cf69641 100644 --- a/.gitea/workflows/security.yml +++ b/.gitea/workflows/security.yml @@ -58,9 +58,15 @@ jobs: # don't look for. Advisory at first (not a required check); promote once tuned. sast: runs-on: ubuntu-latest - container: semgrep/semgrep # official image — the runner's base image lacks pip steps: - uses: actions/checkout@v4 + # The runner image lacks pip, and a semgrep job-container lacks the node that + # actions/checkout needs — so install pip via apt on the standard image. + - name: Install semgrep + run: | + sudo apt-get update -qq && sudo apt-get install -y -qq python3-pip pipx + pipx install semgrep - name: Semgrep scan run: | + export PATH="$HOME/.local/bin:$PATH" semgrep scan --config p/csharp --config p/javascript --config p/security-audit --exclude 'frontend/dist' --exclude '**/bin' --exclude '**/obj' --error --quiet