diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 0955218..97ce58c 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -1,24 +1,25 @@ +name: Semgrep on: workflow_dispatch: {} pull_request: {} push: branches: - - main - - master + - main + - master paths: - - .github/workflows/semgrep.yml + - .github/workflows/semgrep.yml schedule: - # random HH:MM to avoid a load spike on GitHub Actions at 00:00 - - cron: 58 15 * * * -name: Semgrep + # random HH:MM to avoid a load spike on GitHub Actions at 00:00 + - cron: '18 13 * * *' jobs: semgrep: name: semgrep/ci - runs-on: self-hosted + runs-on: ubuntu-20.04 env: SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} container: image: returntocorp/semgrep + if: (github.actor != 'dependabot[bot]') steps: - - uses: actions/checkout@v3 - - run: semgrep ci + - uses: actions/checkout@v3 + - run: semgrep ci