123456789101112131415161718192021222324 |
- on:
- workflow_dispatch: {}
- pull_request: {}
- push:
- branches:
- - main
- - master
- paths:
- - .github/workflows/semgrep.yml
- schedule:
- # random HH:MM to avoid a load spike on GitHub Actions at 00:00
- - cron: 35 14 * * *
- name: Semgrep
- jobs:
- semgrep:
- name: Scan
- runs-on: ubuntu-22.04
- env:
- SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
- container:
- image: returntocorp/semgrep
- steps:
- - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
- - run: semgrep ci
|