semgrep.yml 563 B

1234567891011121314151617181920
  1. name: Semgrep
  2. on: [pull_request]
  3. jobs:
  4. semgrep:
  5. name: Scan
  6. runs-on: ubuntu-latest
  7. steps:
  8. - uses: actions/checkout@v3
  9. - uses: returntocorp/semgrep-action@v1
  10. env: # Optional environment variable for inline PR comments (beta)
  11. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  12. with:
  13. config: |
  14. p/golang
  15. p/r2c-ci
  16. p/r2c-security-audit
  17. p/insecure-transport
  18. p/secrets
  19. publishToken: ${{ secrets.SEMGREP_APP_TOKEN }}
  20. publishDeployment: 241