Add CodeQL security analysis #1
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Semgrep AppSec Analysis | |
| on: | |
| push: | |
| branches: | |
| - master | |
| - security-testing | |
| pull_request: | |
| branches: | |
| - master | |
| - security-testing | |
| workflow_dispatch: | |
| jobs: | |
| analyze: | |
| name: Analyze Python Code | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| actions: read | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Record start time | |
| run: echo "START_TIME=$(date +%s)" >> "$GITHUB_ENV" | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install Semgrep | |
| run: | | |
| python -m pip install --upgrade pip | |
| python -m pip install --upgrade semgrep | |
| - name: Show Semgrep version | |
| run: semgrep --version | |
| - name: Run Semgrep AppSec | |
| continue-on-error: true | |
| env: | |
| SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} | |
| run: | | |
| semgrep ci \ | |
| --sarif \ | |
| --output semgrep_appsec.sarif | |
| - name: Check SARIF file | |
| if: always() | |
| run: | | |
| if [ -f semgrep_appsec.sarif ]; then | |
| echo "SARIF file generated successfully." | |
| ls -lh semgrep_appsec.sarif | |
| else | |
| echo "SARIF file was not generated." | |
| fi | |
| - name: Show SARIF summary | |
| if: always() | |
| run: | | |
| if [ -f semgrep_appsec.sarif ]; then | |
| python - <<'PY' | |
| import json | |
| with open("semgrep_appsec.sarif", encoding="utf-8") as f: | |
| data = json.load(f) | |
| runs = data.get("runs", []) | |
| if not runs: | |
| print("No SARIF runs found") | |
| else: | |
| run = runs[0] | |
| rules = ( | |
| run.get("tool", {}) | |
| .get("driver", {}) | |
| .get("rules", []) | |
| ) | |
| results = run.get("results", []) | |
| print("==============================") | |
| print("Semgrep AppSec SARIF Summary") | |
| print("==============================") | |
| print(f"Rules : {len(rules)}") | |
| print(f"Results : {len(results)}") | |
| severity_count = {} | |
| for result in results: | |
| level = result.get("level", "unknown") | |
| severity_count[level] = severity_count.get(level, 0) + 1 | |
| print("\nResults by severity:") | |
| if severity_count: | |
| for level, count in severity_count.items(): | |
| print(f"{level}: {count}") | |
| else: | |
| print("No vulnerabilities found.") | |
| PY | |
| else | |
| echo "Cannot show summary because SARIF file does not exist." | |
| fi | |
| - name: Record end time and calculate duration | |
| if: always() | |
| run: | | |
| END_TIME=$(date +%s) | |
| DURATION=$((END_TIME - START_TIME)) | |
| echo "Semgrep AppSec pipeline duration: $DURATION seconds" | |
| echo "PIPELINE_DURATION=$DURATION" >> "$GITHUB_ENV" | |
| - name: Upload SARIF results | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: semgrep-appsec-results | |
| path: semgrep_appsec.sarif | |
| if-no-files-found: warn | |
| retention-days: 30 |