ci: run Semgrep from PyPI and upload the report - #16
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
returntocorp/semgrep-action@v1is deprecated. Semgrep archived it, so it takes no fixes and no new rules.The scan runs from PyPI now, the way
vanguardalready runs it: set up Python, install a pinned Semgrep, then callsemgrep scan.The results were going nowhere
The old step asked for SARIF with
generateSarif: "1", and no step ever uploaded it. The file was written inside the runner and thrown away with it, so nothing reached the Security tab of this repository, and thesecurity-events: writepermission went unused.There is an upload step now, guarded so it runs only when the scan wrote a file:
always()matters:--errormakes Semgrep exit non-zero when it finds something, which is exactly when the report is worth reading.Pins
Semgrep is pinned to
1.171.0and Python to3.13, the versionsvanguardruns. A scanner that moves on its own turns a green run red with no change from you.The actions stay pinned to tags, as the rest of this repository pins them.