11on :
22 pull_request :
33
4- name : Semgrep scan
4+ name : Security
55
66jobs :
77 semgrep :
@@ -18,20 +18,19 @@ jobs:
1818 image : semgrep/semgrep
1919
2020 steps :
21- - run : /usr/bin/jq --version
2221 - uses : actions/checkout@v3
2322 with :
2423 fetch-depth : 0
2524 - run : |
26- git clone https://github.com/trailofbits/semgrep-rules $HOME/semgrep-rules-tob
27- git clone https://github.com/semgrep/semgrep-rules $HOME/semgrep-rules
28- git -C $HOME/semgrep-rules reset --hard 518f71b883d431fa33268844b066033507e7c1b5
29- git -C $HOME/semgrep-rules-tob reset --hard 3b91c9b622b4a250b144a832ce73091b1f25e207
30- rm $HOME/semgrep-rules-tob/.github/workflows/update-semgrep-registry.yml
31- rm $HOME/semgrep-rules/.pre-commit-config.yaml
32- rm -rf $HOME/semgrep-rules-tob/.github
33- rm -rf $HOME/semgrep-rules/.github
34- rm -rf $HOME/semgrep-rules/stats
25+ git clone https://github.com/trailofbits/semgrep-rules $HOME/semgrep-rules-tob
26+ git clone https://github.com/semgrep/semgrep-rules $HOME/semgrep-rules
27+ git -C $HOME/semgrep-rules reset --hard 518f71b883d431fa33268844b066033507e7c1b5
28+ git -C $HOME/semgrep-rules-tob reset --hard 3b91c9b622b4a250b144a832ce73091b1f25e207
29+ rm $HOME/semgrep-rules-tob/.github/workflows/update-semgrep-registry.yml
30+ rm $HOME/semgrep-rules/.pre-commit-config.yaml
31+ rm -rf $HOME/semgrep-rules-tob/.github
32+ rm -rf $HOME/semgrep-rules/.github
33+ rm -rf $HOME/semgrep-rules/stats
3534 - run : git config --global --add safe.directory $(pwd)
3635 - run : |
3736 semgrep scan --config $HOME/semgrep-rules --config $HOME/semgrep-rules-tob \
4342 --exclude="*.html" --exclude="*.js" \
4443 --baseline-commit=${{ github.event.pull_request.base.sha }} \
4544 --json > /tmp/semgrep-results.json || true
45+ - run : /usr/bin/jq --version
4646 - name : Notice
4747 shell : bash
4848 run : |
6565 # sarif_file: /tmp/semgrep-results.sarif
6666 # if: always()
6767
68-
0 commit comments