ci(security): install semgrep via apt+pipx on the runner image
CI / backend (pull_request) Successful in 1m2s
CI / frontend (pull_request) Successful in 16s
CI / format (pull_request) Successful in 55s
CI / db-tests (pull_request) Successful in 1m3s
Security / secrets (pull_request) Successful in 4s
Security / dependencies (pull_request) Successful in 1m4s
Security / sast (pull_request) Successful in 54s

The semgrep job-container approach fails because actions/checkout needs node
inside the container. Install pipx via apt on the standard image instead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-02 18:17:13 +02:00
parent b79f35f40e
commit e000332b95
+7 -1
View File
@@ -58,9 +58,15 @@ jobs:
# don't look for. Advisory at first (not a required check); promote once tuned.
sast:
runs-on: ubuntu-latest
container: semgrep/semgrep # official image — the runner's base image lacks pip
steps:
- uses: actions/checkout@v4
# The runner image lacks pip, and a semgrep job-container lacks the node that
# actions/checkout needs — so install pip via apt on the standard image.
- name: Install semgrep
run: |
sudo apt-get update -qq && sudo apt-get install -y -qq python3-pip pipx
pipx install semgrep
- name: Semgrep scan
run: |
export PATH="$HOME/.local/bin:$PATH"
semgrep scan --config p/csharp --config p/javascript --config p/security-audit --exclude 'frontend/dist' --exclude '**/bin' --exclude '**/obj' --error --quiet