File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1-
1+ name : Semgrep OSS scan
22on :
33 pull_request : {}
4+ push :
5+ branches : [main, master]
46 workflow_dispatch : {}
5- push :
6- branches :
7- - main
8- - master
97 schedule :
10- - cron : ' 0 0 * * *'
11- name : Semgrep config
8+ - cron : ' 0 0 15 * *'
9+ concurrency :
10+ group : semgrep-${{ github.event_name }}-${{ github.head_ref || github.run_id }}
11+ cancel-in-progress : true
12+ permissions :
13+ contents : read
1214jobs :
1315 semgrep :
14- name : semgrep/ci
15- runs-on : ubuntu-20.04
16- env :
17- SEMGREP_APP_TOKEN : ${{ secrets.SEMGREP_APP_TOKEN }}
18- SEMGREP_URL : https://cloudflare.semgrep.dev
19- SEMGREP_APP_URL : https://cloudflare.semgrep.dev
20- SEMGREP_VERSION_CHECK_URL : https://cloudflare.semgrep.dev/api/check-version
21- container :
22- image : returntocorp/semgrep
16+ name : semgrep-oss
17+ runs-on : ubuntu-slim
2318 steps :
24- - uses : actions/checkout@v3
25- - run : semgrep ci
19+ - uses : actions/checkout@v5
20+ with :
21+ fetch-depth : 1
22+ - id : cache-semgrep
23+ uses : actions/cache@v5
24+ with :
25+ path : ~/.local
26+ key : semgrep-1.160.0-${{ runner.os }}
27+ - if : steps.cache-semgrep.outputs.cache-hit != 'true'
28+ run : pip install --user semgrep==1.160.0
29+ - run : echo "$HOME/.local/bin" >> "$GITHUB_PATH"
30+ - run : semgrep scan --config=auto
You can’t perform that action at this time.
0 commit comments