diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 2b29db1..06d214a 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -34,9 +34,6 @@ workflows: - 'hyperpolymath/smtp-notify-action@22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': [] - '.github/workflows/semgrep.yml': - - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'github/codeql-action@1c5b675653bb5c22dbe9b12b556ec555138e09fd' '.github/workflows/workflow-linter.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' dependencies: diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml deleted file mode 100644 index 8d2dbad..0000000 --- a/.github/workflows/semgrep.yml +++ /dev/null @@ -1,38 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. -name: Semgrep SAST - -on: - push: - branches: [main, master] - pull_request: - branches: [main, master] - schedule: - - cron: '0 5 * * 1' - workflow_dispatch: - -permissions: - contents: read - -jobs: - semgrep: - runs-on: ubuntu-latest - timeout-minutes: 15 - permissions: - security-events: write - contents: read - container: - image: semgrep/semgrep - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - - name: Run Semgrep - run: semgrep scan --sarif --output=semgrep.sarif --config=auto . - env: - SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} - - - name: Upload SARIF - uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 - with: - sarif_file: semgrep.sarif - if: always()