mirror of
https://github.com/cloudflare/pages-action
synced 2024-12-19 15:00:31 +00:00

Updating Semgrep.yml file - Semgrep is a tool that will be used to scan Cloudflare's public repos for Supply chain, code and secrets. This work is part of Application & Product Security team's initiative to onboard Semgrep onto all of Cloudflare's public repos. In case of any questions, please reach out to "Hrushikesh Deshpande" on cf internal chat.
25 lines
591 B
YAML
25 lines
591 B
YAML
on:
|
|
pull_request: {}
|
|
workflow_dispatch: {}
|
|
push:
|
|
branches:
|
|
- main
|
|
- master
|
|
schedule:
|
|
- cron: '0 0 * * *'
|
|
name: Semgrep config
|
|
jobs:
|
|
semgrep:
|
|
name: semgrep/ci
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
|
|
SEMGREP_URL: https://cloudflare.semgrep.dev
|
|
SEMGREP_APP_URL: https://cloudflare.semgrep.dev
|
|
SEMGREP_VERSION_CHECK_URL: https://cloudflare.semgrep.dev/api/check-version
|
|
container:
|
|
image: returntocorp/semgrep
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- run: semgrep ci
|