Skip to content

Bump github.com/tomarrell/wrapcheck/v2 from 2.8.2 to 2.9.0 #60

Bump github.com/tomarrell/wrapcheck/v2 from 2.8.2 to 2.9.0

Bump github.com/tomarrell/wrapcheck/v2 from 2.8.2 to 2.9.0 #60

Workflow file for this run

name: Semgrep
on:
push:
branches:
- main
permissions: read-all
jobs:
semgrep:
name: Semgrep
runs-on: ubuntu-22.04
permissions:
security-events: write # To upload SARIF results
container:
image: returntocorp/semgrep
steps:
- name: Checkout repository
uses: actions/checkout@v4.1.6
- name: Install Go
uses: actions/setup-go@v5.0.2
with:
go-version-file: go.mod
- name: Verify action checksums
env:
JOB: ${{ github.job }}
WORKFLOW: ${{ github.workflow_ref }}
run: |
WORKFLOW=$(echo "$WORKFLOW" | cut -d '@' -f 1 | cut -d '/' -f 3-5)
go run ./cmd/ghasum verify -cache /__w/_actions -no-evict -offline "$WORKFLOW:$JOB"
- name: Perform Semgrep analysis
run: semgrep ci --sarif --output semgrep.sarif
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
- name: Upload Semgrep report to GitHub
uses: github/codeql-action/upload-sarif@v3.26.0
if: ${{ failure() || success() }}
with:
sarif_file: semgrep.sarif