Skip to content

build(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 #39

build(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6

build(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 #39

Workflow file for this run

name: Security Scan
on:
pull_request:
push:
branches:
- main
workflow_dispatch:
workflow_call:
permissions:
contents: read
security-events: write
jobs:
semgrep:
name: Semgrep
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Semgrep
run: |
python -m pip install --upgrade pip
python -m pip install semgrep==1.168.0
- name: Run Semgrep
id: semgrep
continue-on-error: true
env:
SEMGREP_SEND_METRICS: "off"
run: |
set +e
semgrep scan --config p/default --sarif --output semgrep.sarif --error
scan_status=$?
semgrep scan --config p/default --json --output semgrep.json
echo "exit_code=${scan_status}" >> "$GITHUB_OUTPUT"
exit "${scan_status}"
- name: Upload SARIF report
if: always()
continue-on-error: true
uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
sarif_file: semgrep.sarif
- name: Upload JSON report
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: semgrep-report
path: semgrep.json
if-no-files-found: ignore
- name: Summarize Semgrep report
if: always()
run: |
{
echo "## Semgrep"
echo
if [ -f semgrep.json ]; then
echo "Semgrep completed with exit code: ${{ steps.semgrep.outputs.exit_code }}"
echo
echo "Semgrep findings are reported as artifacts and SARIF, but this workflow only fails for high-or-higher pnpm audit vulnerabilities."
else
echo "Semgrep report was not generated."
fi
} >> "$GITHUB_STEP_SUMMARY"