File tree Expand file tree Collapse file tree 4 files changed +25
-6
lines changed
Expand file tree Collapse file tree 4 files changed +25
-6
lines changed Original file line number Diff line number Diff line change 6969 uses : github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
7070 with :
7171 category : " /language:${{matrix.language}}"
72+
73+ - name : " Upload artifacts"
74+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
75+ with :
76+ name : CodeQL SARIF files
77+ path : ../results
78+ retention-days : 5
Original file line number Diff line number Diff line change 3434 uses : microsoft/DevSkim-Action@4b5047945a44163b94642a1cecc0d93a3f428cc6 # v1.0.16
3535 with :
3636 should-scan-archives : true
37+ - name : " Upload artifact"
38+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
39+ with :
40+ name : DevSkim SARIF file
41+ path : devskim-results.sarif
42+ retention-days : 5
3743 - name : Upload DevSkim scan results to GitHub Security tab
3844 uses : github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
3945 with :
Original file line number Diff line number Diff line change 2929 with :
3030 persist-credentials : false
3131 - name : Run Microsoft Security DevOps scanner
32+ id : scan
3233 uses : microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0 # v1.12.0
33- id : msdo
34+ - name : " Upload artifact"
35+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
36+ with :
37+ name : MSDO SARIF file
38+ path : ${{ steps.scan.outputs.sarifFile }}
39+ retention-days : 5
3440 - name : Upload MSDO scan results to GitHub Security tab
3541 uses : github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
3642 with :
37- sarif_file : ${{ steps.msdo .outputs.sarifFile }}
43+ sarif_file : ${{ steps.scan .outputs.sarifFile }}
Original file line number Diff line number Diff line change @@ -32,16 +32,16 @@ jobs:
3232 - name : " Run analysis"
3333 uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
3434 with :
35- results_file : results.sarif
35+ results_file : scorecards- results.sarif
3636 results_format : sarif
3737 publish_results : true
3838 - name : " Upload artifact"
3939 uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
4040 with :
41- name : SARIF file
42- path : results.sarif
41+ name : Scorecards SARIF file
42+ path : scorecards- results.sarif
4343 retention-days : 5
4444 - name : " Upload to code-scanning"
4545 uses : github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
4646 with :
47- sarif_file : results.sarif
47+ sarif_file : scorecards- results.sarif
You can’t perform that action at this time.
0 commit comments