.github/workflows/semgrep.yml
name: Semgrepon: pull_request: {} push: branches: - master jobs: check: if: "! startsWith(github.event.head_commit.message, '[CI Skip]') && (!github.event.pull_request || github.event.pull_request.head.repo.full_name == github.repository)" runs-on: ubuntu-latest steps: - uses: actions/checkout@v2 - uses: returntocorp/semgrep-action@v1 with: auditOn: push publishToken: ${{ secrets.SEMGREP_APP_TOKEN }} publishDeployment: 1395