aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorrugk <[email protected]>2021-06-05 00:21:48 +0200
committerGitHub <[email protected]>2021-06-05 00:21:48 +0200
commit79c0ad16707a8cfacfc4071f8134fe3c0de23ae4 (patch)
tree897d4d97301d7716dee8523e319d4849b67e05b5
parent93138cbbae6d1ada37f3dcb5cba6a4b77a71d0f4 (diff)
downloadprivatebin-siftleft-scan.tar.gz
privatebin-siftleft-scan.tar.bz2
privatebin-siftleft-scan.zip
Add Siftleft scansiftleft-scan
It seems [to cover](https://slscan.io/en/latest/#supported-languages-frameworks) PHP including license check in addition to dependency scanning.
-rw-r--r--.github/workflows/shiftleft-analysis.yml35
1 files changed, 35 insertions, 0 deletions
diff --git a/.github/workflows/shiftleft-analysis.yml b/.github/workflows/shiftleft-analysis.yml
new file mode 100644
index 00000000..18d412a6
--- /dev/null
+++ b/.github/workflows/shiftleft-analysis.yml
@@ -0,0 +1,35 @@
+# This workflow integrates Scan with GitHub's code scanning feature
+# Scan is a free open-source security tool for modern DevOps teams from ShiftLeft
+# Visit https://slscan.io/en/latest/integrations/code-scan for help
+name: SL Scan
+
+on:
+ push:
+ branches: [ master ]
+ pull_request:
+ # The branches below must be a subset of the branches above
+ branches: [ master ]
+ schedule:
+ - cron: '16 22 * * 4'
+
+jobs:
+ Scan-Build:
+ # Scan runs on ubuntu, mac and windows
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/[email protected]
+ # potentially add composer install steo here
+ - name: Perform Scan
+ uses: ShiftLeftSecurity/[email protected]
+ env:
+ WORKSPACE: ""
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ SCAN_AUTO_BUILD: true
+ with:
+ output: reports
+ # Scan auto-detects the languages.
+
+ - name: Upload report
+ uses: github/codeql-action/[email protected]
+ with:
+ sarif_file: reports