Skip to content

build(deps-dev): bump follow-redirects from 1.15.4 to 1.15.6 #54

build(deps-dev): bump follow-redirects from 1.15.4 to 1.15.6

build(deps-dev): bump follow-redirects from 1.15.4 to 1.15.6 #54

Workflow file for this run

name: Semgrep
on: [workflow_dispatch, push, pull_request]
jobs:
semgrep:
name: Scan
runs-on: ubuntu-latest
container:
image: returntocorp/semgrep
# Skip any PR created by dependabot to avoid permission issues
if: (github.actor != 'dependabot[bot]')
steps:
# Fetch project source
- uses: actions/checkout@v3
- name: semgrep-run
id: semgrep-run
continue-on-error: true
run: |
touch output.log
semgrep ci 2>&1 | tee output.log
env:
# Select rules for your scan with one of these two options.
# Option 1: set hard-coded rulesets
SEMGREP_RULES: >- # more at semgrep.dev/r
p/security-audit
p/secrets
p/ci
p/dockerfile
p/javascript
p/nodejs
- name: upload-logs
if: always()
uses: actions/upload-artifact@v3
with:
name: output.log
path: output.log
retention-days: 1