Skip to content

Commit

Permalink
Upload SARIF files for scanning tools (Azure#2511)
Browse files Browse the repository at this point in the history
  • Loading branch information
BernieWhite authored Nov 3, 2023
1 parent 2370399 commit 3221806
Showing 1 changed file with 73 additions and 38 deletions.
111 changes: 73 additions & 38 deletions .github/workflows/analyze.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,9 @@
name: Analyze
on:
push:
branches: [ main, 'release/*' ]
branches: [main, 'release/*']
pull_request:
branches: [ main, 'release/*' ]
branches: [main, 'release/*']
schedule:
- cron: '26 21 * * 0' # At 09:26 PM, on Sunday each week
workflow_dispatch:
Expand All @@ -31,16 +31,33 @@ jobs:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:

- name: Checkout
uses: actions/checkout@v4

- name: Run PSRule analysis
uses: microsoft/[email protected]
with:
modules: PSRule.Rules.MSFT.OSS
prerelease: true
- name: Checkout
uses: actions/checkout@v4

- name: Run PSRule analysis
uses: microsoft/[email protected]
with:
modules: PSRule.Rules.MSFT.OSS
prerelease: true
outputFormat: Sarif
outputPath: reports/ps-rule-results.sarif

- name: Upload results to security tab
uses: github/codeql-action/upload-sarif@v2
if: always()
with:
sarif_file: reports/ps-rule-results.sarif

- name: Upload results
uses: actions/upload-artifact@v3
if: always()
with:
name: PSRule-Sarif
path: reports/ps-rule-results.sarif
retention-days: 1
if-no-files-found: error

devskim:
name: Analyze with DevSkim
Expand All @@ -50,19 +67,28 @@ jobs:
contents: read
security-events: write
steps:

- name: Checkout
uses: actions/checkout@v4

- name: Run DevSkim scanner
uses: microsoft/DevSkim-Action@v1
with:
directory-to-scan: .

- name: Upload results to security tab
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: devskim-results.sarif
- name: Checkout
uses: actions/checkout@v4

- name: Run DevSkim scanner
uses: microsoft/DevSkim-Action@v1
with:
directory-to-scan: .

- name: Upload results to security tab
uses: github/codeql-action/upload-sarif@v2
if: always()
with:
sarif_file: devskim-results.sarif

- name: Upload results
uses: actions/upload-artifact@v3
if: always()
with:
name: DevSkim-Sarif
path: devskim-results.sarif
retention-days: 1
if-no-files-found: error

codeql:
name: Analyze with CodeQL
Expand All @@ -72,17 +98,26 @@ jobs:
contents: read
security-events: write
steps:

- name: Checkout
uses: actions/checkout@v4

- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: csharp

- name: Autobuild
uses: github/codeql-action/autobuild@v2

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
- name: Checkout
uses: actions/checkout@v4

- name: Initialize CodeQL
uses: github/codeql-action/init@v2
with:
languages: 'csharp'

- name: Autobuild
uses: github/codeql-action/autobuild@v2

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
id: codeql-analyze

- name: Upload results
uses: actions/upload-artifact@v3
if: always()
with:
name: CodeQL-Sarif
path: ${{ steps.codeql-analyze.outputs.sarif-output }}
retention-days: 1
if-no-files-found: error

0 comments on commit 3221806

Please sign in to comment.