digitalfabrik/integreat-cms

View on GitHub
.github/workflows/ossar-analysis.yml

Summary

Maintainability
Test Coverage
# This workflow integrates a collection of open source static analysis tools
# with GitHub code scanning. For documentation, or to provide feedback, visit
# https://github.com/github/ossar-action
name: "OSSAR"

on:
  push:
    branches: [develop]
  pull_request:
    branches: [develop]

permissions:
  contents: read

jobs:
  scan:
    name: Scan
    runs-on: windows-latest

    permissions:
      contents: read # for actions/checkout to fetch code
      security-events: write # for github/codeql-action/upload-sarif to upload SARIF results

    steps:
      # Checkout your code repository to scan
      - name: Checkout repository
        uses: actions/checkout@v4

        # Run open source static analysis tools
      - name: Run OSSAR
        uses: github/ossar-action@v1
        id: ossar

        # Upload results to the Security tab
      - name: Upload OSSAR results
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: ${{ steps.ossar.outputs.sarifFile }}
          category: ossar