Update workflow

This commit is contained in:
Yong Yan 2021-06-23 12:23:34 -07:00
parent ce83692cd3
commit 70014135c9
1 changed files with 12 additions and 3 deletions

View File

@ -1,9 +1,13 @@
on: [push] on: [push]
jobs: jobs:
sarif: flawfinder:
runs-on: ubuntu-latest
name: Flawfinder name: Flawfinder
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
steps: steps:
# To use this repository's private action, # To use this repository's private action,
# you must check out the repository # you must check out the repository
@ -13,4 +17,9 @@ jobs:
- name: Flawfinder action step - name: Flawfinder action step
uses: ./ # Uses an action in the root directory uses: ./ # Uses an action in the root directory
with: with:
command: '--version' command: '--sarif ./ > flawfinder-results.sarif'
- name: Upload analysis results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v1
with:
sarif_file: flawfinder-results.sarif