Skip to content
This repository has been archived by the owner on Aug 1, 2023. It is now read-only.

facebookarchive/sapp-action

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SAPP Github Action

test License: MIT

SAPP Github Action allows you run SAPP (Static Analysis Post Processor) in CI to post process static analysis results from tools like Pysa and Mariana Trench.

SAPP Action will upload the results after applying filters in SARIF to GitHub, where you can view them in the Security tab of your repo.

Usage

# .github/workflows/test.yml

- name: Saving static analysis results for SAPP
    uses: actions/upload-artifact@v2
    with:
        name: static-analysis-results
        path: ./path/to/static-analysis-output
        if-no-files-found: error

- name: Postprocess static analysis results
  uses: facebook/sapp-action@main
  with:
    version: latest # version of fb-sapp on PyPi you want to use
    artifact-handle: static-analysis-results
    filters-directory: /path/to/sapp/filters

License

SAPP Action is licensed under the MIT license.