Skip to content

Commit

Permalink
Merge pull request #1 from zenfosec/shiftleft-action-config-1690868361
Browse files Browse the repository at this point in the history
Add GitHub Action: Qwiet preZero Static Analysis
  • Loading branch information
zenfosec authored Aug 1, 2023
2 parents 6b2d9eb + 8f43f7d commit 726104a
Show file tree
Hide file tree
Showing 2 changed files with 82 additions and 0 deletions.
67 changes: 67 additions & 0 deletions .github/workflows/shiftleft.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
# This workflow integrates ShiftLeft NG SAST with GitHub
# Visit https://docs.shiftleft.io for help
name: ShiftLeft

on:
pull_request:
workflow_dispatch:

jobs:
NextGen-Static-Analysis:
runs-on: ubuntu-20.04
steps:
- uses: actions/checkout@v3
- name: Download ShiftLeft CLI
run: |
curl https://cdn.shiftleft.io/download/sl > ${GITHUB_WORKSPACE}/sl && chmod a+rx ${GITHUB_WORKSPACE}/sl
- name: Extract branch name
shell: bash
run: echo "##[set-output name=branch;]$(echo ${GITHUB_REF#refs/heads/})"
id: extract_branch
- name: NextGen Static Analysis
run: |
pip install -r requirements.txt
${GITHUB_WORKSPACE}/sl analyze --strict --wait --app spoonmap --container 18fgsa/s3-resource --tag branch=${{ github.head_ref || steps.extract_branch.outputs.branch }} --python $(pwd)
env:
SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }}
SHIFTLEFT_API_HOST: www.shiftleft.io
SHIFTLEFT_GRPC_TELEMETRY_HOST: telemetry.shiftleft.io:443
SHIFTLEFT_GRPC_API_HOST: api.shiftleft.io:443
if:
${{ hashFiles('requirements.txt') != '' }}
- name: Legacy Static Analysis
run: |
echo "Please update your `shiftleft-python-demo` fork!"
${GITHUB_WORKSPACE}/sl analyze --strict --wait --no-cpg --app spoonmap --tag branch=${{ github.head_ref || steps.extract_branch.outputs.branch }} --python $(pwd)
env:
SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }}
SHIFTLEFT_API_HOST: www.shiftleft.io
SHIFTLEFT_GRPC_TELEMETRY_HOST: telemetry.shiftleft.io:443
SHIFTLEFT_GRPC_API_HOST: api.shiftleft.io:443
if:
${{ hashFiles('requirements.txt') == '' }}

## Uncomment the following section to enable build rule checking and enforcing.
#Build-Rules:
#runs-on: ubuntu-latest
#needs: NextGen-Static-Analysis
#steps:
#- uses: actions/checkout@v3
#- name: Download ShiftLeft CLI
# run: |
# curl https://cdn.shiftleft.io/download/sl > ${GITHUB_WORKSPACE}/sl && chmod a+rx ${GITHUB_WORKSPACE}/sl
#- name: Validate Build Rules
# run: |
# ${GITHUB_WORKSPACE}/sl check-analysis --app spoonmap \
# --branch '${{ github.event.pull_request.base.ref }}' \
# --target 'tag.branch=${{ github.head_ref || steps.extract_branch.outputs.branch }}' \
# --github-pr-number=${{github.event.number}} \
# --github-pr-user=${{ github.repository_owner }} \
# --github-pr-repo=${{ github.event.repository.name }} \
# --github-token=${{ secrets.GITHUB_TOKEN }}
# env:
#SHIFTLEFT_ACCESS_TOKEN: ${{ secrets.SHIFTLEFT_ACCESS_TOKEN }}
#SHIFTLEFT_API_HOST: www.shiftleft.io
#SHIFTLEFT_GRPC_API_HOST: api.shiftleft.io:443
#SHIFTLEFT_GRPC_TELEMETRY_HOST: telemetry.shiftleft.io:443
15 changes: 15 additions & 0 deletions shiftleft.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
version: 2
build_rules:
- id: Allow no critical findings
severities:
- critical
- id: Allow one OSS or container finding
finding_types:
- oss_vuln
- container
threshold: 1
- id: Allow no reachable OSS vulnerability
finding_types:
- oss_vuln
options:
reachable: true

0 comments on commit 726104a

Please sign in to comment.