.github/workflows/ossar-analysis.yml
# This workflow integrates a collection of open source static analysis tools
# with GitHub code scanning. For documentation, or to provide feedback, visit
# https://github.com/github/ossar-action
name: "OSSAR"
on:
push:
branches: [develop]
pull_request:
branches: [develop]
permissions:
contents: read
jobs:
scan:
name: Scan
runs-on: windows-latest
permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
steps:
# Checkout your code repository to scan
- name: Checkout repository
uses: actions/checkout@v4
# Run open source static analysis tools
- name: Run OSSAR
uses: github/ossar-action@v1
id: ossar
# Upload results to the Security tab
- name: Upload OSSAR results
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ steps.ossar.outputs.sarifFile }}
category: ossar