Skip to content

ci: add Semgrep OSS scanning workflow#15

Merged
elithrar merged 1 commit into
mainfrom
hrushikesh/add-semgrep-oss-workflow
Apr 29, 2026
Merged

ci: add Semgrep OSS scanning workflow#15
elithrar merged 1 commit into
mainfrom
hrushikesh/add-semgrep-oss-workflow

Conversation

@hrushikeshdeshpande

Copy link
Copy Markdown
Contributor

Summary

Adds Semgrep Community Edition (OSS) scanning to this repository as part of the App&ProdSec team's migration from Semgrep Pro to Semgrep CE.

What it does

  • Runs on every PR, on push to the main/master branch, and monthly on a staggered schedule.
  • Uses actions/cache@v5 so pip install semgrep only runs on cold cache (first run, version bump, or 7-day idle).
  • Pinned to semgrep==1.160.0 with --config=auto (default OSS ruleset).
  • Runs on ubuntu-slim with contents: read token scope.

For reviewers

  • Findings are informational; the job does not block on findings.
  • First PR after merge installs Semgrep; subsequent PRs skip that step.

See the internal App&ProdSec email for migration context, or ping us internally.

@github-actions github-actions Bot added the potential-low-quality-pr Summary-template issue/PR or large PR from a new account label Apr 23, 2026
@elithrar elithrar merged commit d2ce288 into main Apr 29, 2026
6 checks passed
@elithrar elithrar deleted the hrushikesh/add-semgrep-oss-workflow branch April 29, 2026 01:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

potential-low-quality-pr Summary-template issue/PR or large PR from a new account

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants