ci(semgrep): run in the official Semgrep container (setup-python failed on the runner)
The setup-python + `pip install semgrep` step errored on the Gitea runner. Switch to `container: docker.io/semgrep/semgrep` (semgrep preinstalled) — the documented way to run Semgrep in CI, and the exact execution verified locally (306 rules / 450 files, 27 findings, exit 0). Fully-qualified image name so short-name resolution works under Docker or podman. Still report-only (no --error); WP-30 tracks flipping to blocking. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -112,17 +112,17 @@ jobs:
|
|||||||
# SAST for both sides — replaces CodeQL, which is GitHub-only (its analyze step uploads
|
# SAST for both sides — replaces CodeQL, which is GitHub-only (its analyze step uploads
|
||||||
# SARIF to GitHub's code-scanning API) and can't run on this Gitea instance. Semgrep OSS
|
# SARIF to GitHub's code-scanning API) and can't run on this Gitea instance. Semgrep OSS
|
||||||
# is a plain CLI: no account, no external platform API. Findings print in the job log.
|
# is a plain CLI: no account, no external platform API. Findings print in the job log.
|
||||||
|
# Runs in the official Semgrep image (semgrep preinstalled) — the setup-python + pip
|
||||||
|
# approach failed on this runner. Fully-qualified image name so short-name resolution
|
||||||
|
# works regardless of the container engine (Docker or podman).
|
||||||
# ponytail: report-only for now (no `--error`, so the job stays green while the initial
|
# ponytail: report-only for now (no `--error`, so the job stays green while the initial
|
||||||
# findings are triaged); flip to `--error` to make it a blocking gate. See WP-30.
|
# findings are triaged); flip to `--error` to make it a blocking gate. See WP-30.
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
|
container:
|
||||||
|
image: docker.io/semgrep/semgrep
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- uses: actions/setup-python@v5
|
|
||||||
with:
|
|
||||||
python-version: '3.12'
|
|
||||||
cache: pip
|
|
||||||
- run: pip install semgrep
|
|
||||||
# p/default = curated cross-language security (covers JS/TS); p/csharp = the backend.
|
# p/default = curated cross-language security (covers JS/TS); p/csharp = the backend.
|
||||||
# Anonymous registry fetch; --metrics=off disables telemetry (not `auto`, which uploads
|
# Anonymous registry fetch; --metrics=off disables telemetry (not `auto`, which uploads
|
||||||
# project metadata).
|
# project metadata).
|
||||||
|
|||||||
Reference in New Issue
Block a user