Skip to content

Commit 07bf2bf

Browse files
authored
Add AST Scan (#783)
1 parent eda3bf6 commit 07bf2bf

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed

.github/workflows/ast-scan.yml

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: Checkmarx One Scan
2+
on:
3+
workflow_dispatch:
4+
pull_request:
5+
push:
6+
branches:
7+
- main
8+
schedule:
9+
- cron: '00 7 * * *' # Every day at 07:00
10+
11+
jobs:
12+
cx-scan:
13+
name: Checkmarx One Scan
14+
runs-on: ubuntu-latest
15+
steps:
16+
- name: Checkout
17+
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
18+
- name: Checkmarx One CLI Action
19+
uses: checkmarx/ast-github-action@03a90e7253dadd7e2fff55f5dfbce647b39040a1 # v.2.0.37
20+
with:
21+
base_uri: ${{ secrets.AST_RND_SCANS_BASE_URI }}
22+
cx_tenant: ${{ secrets.AST_RND_SCANS_TENANT }}
23+
cx_client_id: ${{ secrets.AST_RND_SCANS_CLIENT_ID }}
24+
cx_client_secret: ${{ secrets.AST_RND_SCANS_CLIENT_SECRET }}
25+
additional_params: --tags phoenix --threshold "sca-critical=1;sca-high=1;sca-medium=1;sca-low=1;sast-critical=1;sast-high=1;sast-medium=1;sast-low=1;iac-security-critical=1;iac-security-high=1;iac-security-medium=1;iac-security-low=1"

0 commit comments

Comments
 (0)