Skip to content

chore(deps): update module sigs.k8s.io/structured-merge-diff/v4 to v7 #669

chore(deps): update module sigs.k8s.io/structured-merge-diff/v4 to v7

chore(deps): update module sigs.k8s.io/structured-merge-diff/v4 to v7 #669

Workflow file for this run

name: Semgrep
on:
# Scan changed files in PRs, block on new issues only (existing issues ignored)
pull_request: {}
jobs:
semgrep:
name: Scan
runs-on: ubuntu-latest
# Skip any PR created by dependabot to avoid permission issues
if: (github.actor != 'dependabot[bot]')
container:
image: semgrep/semgrep:1.180.0@sha256:529ee8a277ec8adc5b534d7c74eea0a47e9de21d62852b6ba7ac6ba9566845c3
steps:
# Fetch project source
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Run Semgrep
run: |
semgrep scan \
--sarif \
--output=semgrep.sarif \
--config="p/security-audit" \
--config="p/secrets" \
--config="p/ci" \
--config="p/default" \
--config="p/docker" \
--config="p/dockerfile" \
--config="p/command-injection"
# Upload findings to GitHub Advanced Security Dashboard [step 2/2]
- name: Upload SARIF file for GitHub Advanced Security Dashboard
uses: github/codeql-action/upload-sarif@24c54180a607b1449ed407dd24f251e4e9147c8d # v4.38.3
with:
sarif_file: semgrep.sarif