Skip to content

Amplify Security

Amplify Security #138

Workflow file for this run

# .github/workflows/amplify.yml
name: Amplify Security
on:
pull_request: {}
workflow_dispatch: {}
push:
branches: ["master", "main"]
jobs:
amplify-security-scan:
runs-on: ubuntu-latest
container:
image: returntocorp/semgrep
if: (github.actor != 'dependabot[bot]')
steps:
- uses: actions/checkout@v3
- run: semgrep ci --config auto --json > amplify-sast.json || true
env:
SEMGREP_RULES: >-
p/security-audit
p/secrets
- uses: actions/upload-artifact@v3
with:
name: amplify-scan
path: amplify-sast.json
retention-days: 7