Repository navigation
112 lines (93 loc) · 3.41 KB
/
Copy pathsemgrep.yml
File metadata and controls
112 lines (93 loc) · 3.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
name: Semgrep Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# Run daily at 00:00 UTC to catch new vulnerabilities
- cron: '0 0 * * *'
permissions:
contents: read
actions: read # Required by codeql-action/upload-sarif to read workflow run info
security-events: write # Required for SARIF upload
pull-requests: write # For PR comments
jobs:
semgrep:
runs-on: ubuntu-latest
# Skip scheduled runs on forks
if: (github.event_name != 'schedule') || (github.repository == 'cryptnox/cryptnox-cli')
container:
# Official Semgrep Docker image
image: semgrep/semgrep
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Fix Git ownership in container
run: |
git config --global --add safe.directory /__w/cryptnox-cli/cryptnox-cli || true
git config --global --add safe.directory "$GITHUB_WORKSPACE" || true
- name: Run Semgrep Security Scan
id: semgrep
continue-on-error: true
run: |
echo "Running Semgrep security analysis..."
echo "===================================="
echo ""
# 1. Run Semgrep with text output to console (for logs)
# We use --error to ensure it fails if issues are found
semgrep scan \
--config=p/python \
--config=p/security-audit \
--config=p/owasp-top-ten \
--verbose \
--metrics=off
# Capture exit code from the text scan
EXIT_CODE=$?
echo ""
echo "Generating SARIF report..."
# 2. Generate SARIF report for GitHub Security
semgrep scan \
--config=p/python \
--config=p/security-audit \
--config=p/owasp-top-ten \
--sarif \
--output=semgrep.sarif \
--metrics=off || true
# Verify SARIF file was created
if [ -f semgrep.sarif ]; then
echo "✓ SARIF file created successfully"
ls -lh semgrep.sarif
else
echo "⚠️ Warning: SARIF file not created"
fi
# Return the exit code from the text scan
exit $EXIT_CODE
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
- name: Upload Semgrep SARIF to GitHub Security
if: always() && hashFiles('semgrep.sarif') != ''
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: semgrep.sarif
category: semgrep
- name: Upload Semgrep reports as artifacts
if: always()
uses: actions/upload-artifact@v4
with:
name: semgrep-reports
path: semgrep.sarif
if-no-files-found: warn
- name: Check Semgrep results
if: steps.semgrep.outcome == 'failure'
run: |
echo "⚠️ Semgrep found security issues"
echo ""
echo "Review the findings:"
echo " 1. Check the output above for details"
echo " 2. Go to Security -> Code scanning -> Semgrep category"
echo " 3. Download artifacts for full reports"
echo ""
echo "Note: Some findings may be false positives."
echo "Review each one carefully before taking action."
exit 1