Skip to content

Commit ae81e30

Browse files
author
Matt Peake
committed
ci: add semgrep job
1 parent a778ca1 commit ae81e30

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

.circleci/config.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ version: 2.1
22

33
orbs:
44
node: circleci/node@5.0.2
5+
secops: apollo/circleci-secops-orb@2.0.6
56

67
commands:
78
install-volta:
@@ -95,3 +96,16 @@ workflows:
9596
- Linting
9697
- Query Check
9798
- Generated Types Check
99+
security-scans:
100+
jobs:
101+
- secops/gitleaks:
102+
context:
103+
- secops-oidc
104+
- github-orb
105+
git-base-revision: <<#pipeline.git.base_revision>><<pipeline.git.base_revision>><</pipeline.git.base_revision >>
106+
git-revision: << pipeline.git.revision >>
107+
- secops/semgrep:
108+
context:
109+
- secops-oidc
110+
- github-orb
111+
git-base-revision: <<#pipeline.git.base_revision>><<pipeline.git.base_revision>><</pipeline.git.base_revision >>

0 commit comments

Comments
 (0)