diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml deleted file mode 100644 index b5865bdd..00000000 --- a/.github/workflows/security.yml +++ /dev/null @@ -1,49 +0,0 @@ -name: SecurityChecks -on: - pull_request: {} - push: - branches: ["master"] -jobs: - semgrep: - name: Scan - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v2 - - uses: returntocorp/semgrep-action@v1 - with: - publishToken: ${{ secrets.SEMGREP_APP_TOKEN }} - publishDeployment: 339 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - workflow_status: - runs-on: ubuntu-latest - name: Update Status Check - needs: [ semgrep ] - if: always() - env: - githubCommit: ${{ github.event.pull_request.head.sha }} - steps: - - name: Set github commit id - run: | - if [ "${{ github.event_name }}" = "push" ]; then - echo "githubCommit=${{ github.sha }}" >> $GITHUB_ENV - fi - exit 0 - - name: Failed - id: failed - if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') - run: | - echo 'Failing the workflow for github security status check.' - curl -X POST -H "Content-Type: application/json" -H "Authorization: token ${{ github.token }}" \ - -d '{ "state" : "failure" , "context" : "github/security-status-check" , "description" : "github/security-status-check", "target_url" : "https://github.com/${{ github.repository }}" }' \ - https://api.github.com/repos/${{ github.repository }}/statuses/${{ env.githubCommit }} - exit 1 - - name: Success - if: steps.failed.conclusion == 'skipped' - run: | - echo 'Status check has passed!' - curl -X POST -H "Content-Type: application/json" -H "Authorization: token ${{ github.token }}" \ - -d '{ "state" : "success" , "context" : "github/security-status-check" , "description" : "github/security-status-check", "target_url" : "https://github.com/${{ github.repository }}" }' \ - https://api.github.com/repos/${{ github.repository }}/statuses/${{ env.githubCommit }} - exit 0 diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml deleted file mode 100644 index 60f53777..00000000 --- a/.github/workflows/semgrep.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: Semgrep -on: - pull_request: {} - push: - branches: ["master"] -jobs: - semgrep: - name: Scan - runs-on: ubuntu-latest - # Skip any PR created by dependabot to avoid permissioning issues - if: (github.actor != 'dependabot[bot]') - steps: - - uses: actions/checkout@v2 - - uses: returntocorp/semgrep-action@v1 - with: - auditOn: push - publishToken: ${{ secrets.SEMGREP_APP_TOKEN }} - publishDeployment: 339 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.semgrepignore b/.semgrepignore deleted file mode 100644 index de40e454..00000000 --- a/.semgrepignore +++ /dev/null @@ -1,33 +0,0 @@ -# Copied from https://github.com/returntocorp/semgrep-action/blob/develop/src/semgrep_agent/templates/.semgrepignore - -# Ignore git items -.gitignore -.git/ -:include .gitignore - -# Common large directories -node_modules/ -build/ -dist/ -vendor/ -env/ -.env/ -venv/ -.venv/ -*.min.js - -# Common test directories -test/ -tests/ - -# Semgrep rules folder -.semgrep - -# Metro custom files -third_party/ -coverage/ -*_test.go -*.pb.go -*.pb.*.go - -.github/workflows/