Skip to content

Conversation

@Mrtenz
Copy link
Member

@Mrtenz Mrtenz commented Mar 7, 2025

MetaMask/Security-Code-Scanner was renamed to MetaMask/action-security-code-scanner, and is now properly versioned as well. I've updated the workflow to use MetaMask/action-security-code-scanner@v1, and also changed it to run as part of the main workflow.

Examples

We use this in the Snaps repo: https://github.com/MetaMask/snaps/blob/0d9472d5f4110fdd9b657220a51c53cbac6a2675/.github/workflows/main.yml#L24-L34

@Mrtenz Mrtenz marked this pull request as ready for review March 7, 2025 17:52
@Mrtenz Mrtenz requested a review from a team March 7, 2025 17:52
@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Copy link
Contributor

@mcmire mcmire left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense!

Comment on lines +25 to +36
analyse-code:
name: Code scanner
needs: check-workflows
uses: ./.github/workflows/security-code-scanner.yml
permissions:
actions: read
contents: read
security-events: write
secrets:
SECURITY_SCAN_METRICS_TOKEN: ${{ secrets.SECURITY_SCAN_METRICS_TOKEN }}
APPSEC_BOT_SLACK_WEBHOOK: ${{ secrets.APPSEC_BOT_SLACK_WEBHOOK }}

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does this run in parallel to the other steps? One of the reasons we had originally opted for it to be separate is so that it would execute in parallel to not slow down CI times. Especially the CodeQL step can take a minute or two to build its database depending on the size of the repo

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It does! It only depends on check-workflows, but after that, both the security code scanner and build, lint, test steps will run in parallel.

@Mrtenz Mrtenz merged commit 0bd639c into main Mar 7, 2025
21 checks passed
@Mrtenz Mrtenz deleted the mrtenz/update-security-code-scanner branch March 7, 2025 19:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants