Skip to content

Commit

Permalink
OPSEXP-2121 Add kics scan (#1196)
Browse files Browse the repository at this point in the history
  • Loading branch information
pmacius committed Sep 25, 2024
1 parent 1b7d026 commit 5a7319a
Showing 1 changed file with 39 additions and 0 deletions.
39 changes: 39 additions & 0 deletions .github/workflows/kics.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: kics

on:
pull_request:
branches: [master]
paths:
- 'docker-compose/**'
- 'helm/**'
- '.github/workflows/kics.yml'
push:
branches: [master]
paths:
- 'docker-compose/**'
- 'helm/**'
- '.github/workflows/kics.yml'

permissions:
security-events: write

jobs:
kics:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: run kics Scan
uses: checkmarx/kics-github-action@530ac1f8efe6202b0f12c9a6e952597ae707b755 # v2.1.2
with:
path: 'docker-compose,helm'
ignore_on_exit: results
output_path: report-dir/
output_formats: 'sarif'
token: ${{ secrets.GITHUB_TOKEN }}
enable_jobs_summary: true
platform_type: 'dockercompose,kubernetes'
disable_secrets: true
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@323f5ef653b88011bf10e9a0a56d70d742463c9a # v3.26.8
with:
sarif_file: report-dir/results.sarif

0 comments on commit 5a7319a

Please sign in to comment.