Skip to content

Test Orca IaC action - Sarif #3

Test Orca IaC action - Sarif

Test Orca IaC action - Sarif #3

name: Test Orca IaC action - Sarif
on:
workflow_dispatch:
permissions:
contents: read
security-events: write
jobs:
iac_scan_job:
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # ratchet:actions/checkout@v3
- name: Scan IaC
id: orcasecurity_iac_scan
uses: ./
with:
api_token: ${{ secrets.ORCA_SECURITY_API_TOKEN }}
project_key: "default"
path: "test"
format: "sarif"
output: "results/"
console_output: "cli"
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@ceaec5c11a131e0d282ff3b6f095917d234caace # ratchet:github/codeql-action/upload-sarif@v2
if: ${{ always() && steps.orcasecurity_iac_scan.outputs.exit_code != 1 }}
with:
sarif_file: results/iac.sarif