Skip to content

Add CodeQL security analysis #1

Add CodeQL security analysis

Add CodeQL security analysis #1

Workflow file for this run

name: Semgrep AppSec Analysis
on:
push:
branches:
- master
- security-testing
pull_request:
branches:
- master
- security-testing
workflow_dispatch:
jobs:
analyze:
name: Analyze Python Code
runs-on: ubuntu-latest
permissions:
contents: read
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Record start time
run: echo "START_TIME=$(date +%s)" >> "$GITHUB_ENV"
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install Semgrep
run: |
python -m pip install --upgrade pip
python -m pip install --upgrade semgrep
- name: Show Semgrep version
run: semgrep --version
- name: Run Semgrep AppSec
continue-on-error: true
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
run: |
semgrep ci \
--sarif \
--output semgrep_appsec.sarif
- name: Check SARIF file
if: always()
run: |
if [ -f semgrep_appsec.sarif ]; then
echo "SARIF file generated successfully."
ls -lh semgrep_appsec.sarif
else
echo "SARIF file was not generated."
fi
- name: Show SARIF summary
if: always()
run: |
if [ -f semgrep_appsec.sarif ]; then
python - <<'PY'
import json
with open("semgrep_appsec.sarif", encoding="utf-8") as f:
data = json.load(f)
runs = data.get("runs", [])
if not runs:
print("No SARIF runs found")
else:
run = runs[0]
rules = (
run.get("tool", {})
.get("driver", {})
.get("rules", [])
)
results = run.get("results", [])
print("==============================")
print("Semgrep AppSec SARIF Summary")
print("==============================")
print(f"Rules : {len(rules)}")
print(f"Results : {len(results)}")
severity_count = {}
for result in results:
level = result.get("level", "unknown")
severity_count[level] = severity_count.get(level, 0) + 1
print("\nResults by severity:")
if severity_count:
for level, count in severity_count.items():
print(f"{level}: {count}")
else:
print("No vulnerabilities found.")
PY
else
echo "Cannot show summary because SARIF file does not exist."
fi
- name: Record end time and calculate duration
if: always()
run: |
END_TIME=$(date +%s)
DURATION=$((END_TIME - START_TIME))
echo "Semgrep AppSec pipeline duration: $DURATION seconds"
echo "PIPELINE_DURATION=$DURATION" >> "$GITHUB_ENV"
- name: Upload SARIF results
if: always()
uses: actions/upload-artifact@v4
with:
name: semgrep-appsec-results
path: semgrep_appsec.sarif
if-no-files-found: warn
retention-days: 30