ci(security): Semgrep SAST #32
@@ -58,9 +58,15 @@ jobs:
|
|||||||
# don't look for. Advisory at first (not a required check); promote once tuned.
|
# don't look for. Advisory at first (not a required check); promote once tuned.
|
||||||
sast:
|
sast:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container: semgrep/semgrep # official image — the runner's base image lacks pip
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
# The runner image lacks pip, and a semgrep job-container lacks the node that
|
||||||
|
# actions/checkout needs — so install pip via apt on the standard image.
|
||||||
|
- name: Install semgrep
|
||||||
|
run: |
|
||||||
|
sudo apt-get update -qq && sudo apt-get install -y -qq python3-pip pipx
|
||||||
|
pipx install semgrep
|
||||||
- name: Semgrep scan
|
- name: Semgrep scan
|
||||||
run: |
|
run: |
|
||||||
|
export PATH="$HOME/.local/bin:$PATH"
|
||||||
semgrep scan --config p/csharp --config p/javascript --config p/security-audit --exclude 'frontend/dist' --exclude '**/bin' --exclude '**/obj' --error --quiet
|
semgrep scan --config p/csharp --config p/javascript --config p/security-audit --exclude 'frontend/dist' --exclude '**/bin' --exclude '**/obj' --error --quiet
|
||||||
|
|||||||
Reference in New Issue
Block a user