Skip to content

Commit 06b66f9

Browse files
committed
PXG-000: Add snyk scan to kondukto workflow
1 parent 31b88c9 commit 06b66f9

File tree

1 file changed

+18
-14
lines changed

1 file changed

+18
-14
lines changed

.github/workflows/kondukto.yml

Lines changed: 18 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,15 @@ env:
1212
jobs:
1313
run-scans:
1414
runs-on: ubuntu-latest
15+
strategy:
16+
matrix:
17+
tool:
18+
- dependabot
19+
- semgrep
20+
- osvscannersca
21+
- gitleaks
22+
- trufflehogsecurity
23+
- snyksast
1524

1625
steps:
1726
- name: Checkout Code
@@ -21,17 +30,12 @@ jobs:
2130
run: |
2231
curl -sSL https://cli.kondukto.io | sh
2332
24-
- name: Scan with Dependabot
25-
run: kdt scan --host ${{ secrets.KONDUKTO_HOST }} --token ${{ secrets.KONDUKTO_TOKEN }} -p ${{ secrets.PROJECT_NAME }} -t dependabot -b $TARGET_BRANCH --async
26-
27-
- name: Scan with Semgrep
28-
run: kdt scan --host ${{ secrets.KONDUKTO_HOST }} --token ${{ secrets.KONDUKTO_TOKEN }} -p ${{ secrets.PROJECT_NAME }} -t semgrep -b $TARGET_BRANCH --async
29-
30-
- name: Scan with OSV
31-
run: kdt scan --host ${{ secrets.KONDUKTO_HOST }} --token ${{ secrets.KONDUKTO_TOKEN }} -p ${{ secrets.PROJECT_NAME }} -t osvscannersca -b $TARGET_BRANCH --async
32-
33-
- name: Scan with Gitleaks
34-
run: kdt scan --host ${{ secrets.KONDUKTO_HOST }} --token ${{ secrets.KONDUKTO_TOKEN }} -p ${{ secrets.PROJECT_NAME }} -t gitleaks -b $TARGET_BRANCH --async
35-
36-
- name: Scan with Trufflehog
37-
run: kdt scan --host ${{ secrets.KONDUKTO_HOST }} --token ${{ secrets.KONDUKTO_TOKEN }} -p ${{ secrets.PROJECT_NAME }} -t trufflehogsecurity -b $TARGET_BRANCH --async
33+
- name: Scan with ${{ matrix.tool }}
34+
run: |
35+
kdt scan \
36+
--host ${{ secrets.KONDUKTO_HOST }} \
37+
--token ${{ secrets.KONDUKTO_TOKEN }} \
38+
-p ${{ secrets.PROJECT_NAME }} \
39+
-t ${{ matrix.tool }} \
40+
-b $TARGET_BRANCH \
41+
--async

0 commit comments

Comments
 (0)