Skip to content

Commit 3945407

Browse files
committed
ci(sarif): upload SARIF files
1 parent c964a77 commit 3945407

File tree

4 files changed

+25
-6
lines changed

4 files changed

+25
-6
lines changed

.github/workflows/codeql-analysis.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,3 +69,10 @@ jobs:
6969
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
7070
with:
7171
category: "/language:${{matrix.language}}"
72+
73+
- name: "Upload artifacts"
74+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
75+
with:
76+
name: CodeQL SARIF files
77+
path: ../results
78+
retention-days: 5

.github/workflows/devskim.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,12 @@ jobs:
3434
uses: microsoft/DevSkim-Action@4b5047945a44163b94642a1cecc0d93a3f428cc6 # v1.0.16
3535
with:
3636
should-scan-archives: true
37+
- name: "Upload artifact"
38+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
39+
with:
40+
name: DevSkim SARIF file
41+
path: devskim-results.sarif
42+
retention-days: 5
3743
- name: Upload DevSkim scan results to GitHub Security tab
3844
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
3945
with:

.github/workflows/msdo.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,15 @@ jobs:
2929
with:
3030
persist-credentials: false
3131
- name: Run Microsoft Security DevOps scanner
32+
id: scan
3233
uses: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0 # v1.12.0
33-
id: msdo
34+
- name: "Upload artifact"
35+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
36+
with:
37+
name: MSDO SARIF file
38+
path: ${{ steps.scan.outputs.sarifFile }}
39+
retention-days: 5
3440
- name: Upload MSDO scan results to GitHub Security tab
3541
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
3642
with:
37-
sarif_file: ${{ steps.msdo.outputs.sarifFile }}
43+
sarif_file: ${{ steps.scan.outputs.sarifFile }}

.github/workflows/scorecards.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,16 +32,16 @@ jobs:
3232
- name: "Run analysis"
3333
uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
3434
with:
35-
results_file: results.sarif
35+
results_file: scorecards-results.sarif
3636
results_format: sarif
3737
publish_results: true
3838
- name: "Upload artifact"
3939
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
4040
with:
41-
name: SARIF file
42-
path: results.sarif
41+
name: Scorecards SARIF file
42+
path: scorecards-results.sarif
4343
retention-days: 5
4444
- name: "Upload to code-scanning"
4545
uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
4646
with:
47-
sarif_file: results.sarif
47+
sarif_file: scorecards-results.sarif

0 commit comments

Comments
 (0)