Skip to content
Open

Test #14

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
c98f7b2
Create debricked.yml
devsecops454 Feb 25, 2025
4b1efc6
Update debricked.yml
devsecops454 Feb 25, 2025
1efbd9e
Update debricked.yml
devsecops454 Feb 25, 2025
d97051d
Update README.MD
devsecops454 Feb 28, 2025
90a6dbc
Update README.MD
devsecops454 Feb 28, 2025
213a402
Create codacy.yml
devsecops454 Mar 6, 2025
42e02b7
Update codacy.yml
devsecops454 Mar 6, 2025
8f55b02
Update codacy.yml
devsecops454 Mar 6, 2025
e6d1774
Update codacy.yml
devsecops454 Mar 6, 2025
4982771
Update codacy.yml
devsecops454 Mar 6, 2025
7ef57b7
Add .whitesource configuration file
mend-bolt-for-github[bot] Mar 6, 2025
a770253
Merge pull request #1 from devsecops454/whitesource/configure
devsecops454 Mar 6, 2025
7c57fb8
Update codacy.yml
devsecops454 Mar 6, 2025
99fd10d
Delete .github/workflows/codacy.yml
devsecops454 Mar 6, 2025
21df551
Delete .github/workflows/debricked.yml
devsecops454 Mar 6, 2025
29f7e74
Update .whitesource
devsecops454 Mar 6, 2025
e5ee338
Delete .whitesource
devsecops454 Mar 6, 2025
52e3883
Add .whitesource configuration file
mend-bolt-for-github[bot] Mar 6, 2025
1a3e649
Merge pull request #2 from devsecops454/whitesource/configure
devsecops454 Mar 6, 2025
9af2b5c
Create codacy.yml
devsecops454 Mar 6, 2025
5eacd20
Delete .whitesource
devsecops454 Mar 6, 2025
e5d1868
Add .whitesource configuration file
mend-bolt-for-github[bot] Mar 6, 2025
e392219
Merge pull request #3 from devsecops454/whitesource/configure
devsecops454 Mar 6, 2025
fb7198a
Update codacy.yml
devsecops454 Mar 6, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 62 additions & 0 deletions .github/workflows/codacy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.

# This workflow checks out code, performs a Codacy security scan
# and integrates the results with the
# GitHub Advanced Security code scanning feature. For more information on
# the Codacy security scan action usage and parameters, see
# https://github.com/codacy/codacy-analysis-cli-action.
# For more information on Codacy Analysis CLI in general, see
# https://github.com/codacy/codacy-analysis-cli.

name: Codacy Security Scan

on:
push:
branches: [ "master" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "master" ]
schedule:
- cron: '33 18 * * 1'

permissions:
contents: read

jobs:
codacy-security-scan:
permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
name: Codacy Security Scan
runs-on: ubuntu-latest
steps:
# Checkout the repository to the GitHub Actions runner
- name: Checkout code
uses: actions/checkout@v4

# Execute Codacy Analysis CLI and generate a SARIF output with the security issues identified during the analysis
- name: Run Codacy Analysis CLI
uses: codacy/codacy-analysis-cli-action@d840f886c4bd4edc059706d09c6a1586111c540b
with:
# Check https://github.com/codacy/codacy-analysis-cli#project-token to get your project token from your Codacy repository
# You can also omit the token and run the tools that support default configurations
project-token: ${{ secrets.CODACY_PROJECT_TOKEN }}
#api-token: ${{ secrets.CODACY_API_TOKEN }}
#verbose: true
output: results.sarif
format: sarif
# Adjust severity of non-security issues
gh-code-scanning-compat: true
# Force 0 exit code to allow SARIF file generation
# This will handover control about PR rejection to the GitHub side
max-allowed-issues: 2147483647

# Upload the SARIF file generated in the previous step
- name: Upload SARIF results file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
14 changes: 14 additions & 0 deletions .whitesource
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"scanSettings": {
"baseBranches": []
},
"checkRunSettings": {
"vulnerableCheckRunConclusionLevel": "failure",
"displayMode": "diff",
"useMendCheckNames": true
},
"issueSettings": {
"minSeverityLevel": "LOW",
"issueType": "DEPENDENCY"
}
}