Skip to content

Added semgrep

Added semgrep #13

Workflow file for this run

# This workflow will do a clean installation of node dependencies, cache/restore them, build the source code and run tests across different versions of node
# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-nodejs
name: Node.js CI & Semgrep Scan
on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
jobs:
build:
runs-on: ubuntu-latest
strategy:
matrix:
node-version: [18.x, 20.x, 22.x]
# See supported Node.js release schedule at https://nodejs.org/en/about/releases/
steps:
- uses: actions/checkout@v4
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
cache: 'npm'
- run: npm ci
- run: npm test
semgrep:
name: Semgrep Scan
runs-on: ubuntu-latest
steps:
# It also needs to check out the code to be able to scan it
- name: Checkout repository
uses: actions/checkout@v4
# Run the official Semgrep action
- name: Run Semgrep
uses: returntocorp/semgrep-action@v1
- run: semgrep scan