Bump filelock from 3.32.2 to 3.32.3 #18
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| on: | |
| workflow_dispatch: {} | |
| pull_request: {} | |
| push: | |
| branches: | |
| - main | |
| - master | |
| schedule: | |
| # random HH:MM to avoid a load spike on GitHub Actions at 00:00 | |
| - cron: 34 7 * * * | |
| name: Semgrep | |
| jobs: | |
| semgrep: | |
| name: semgrep/ci | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| container: | |
| image: semgrep/semgrep | |
| steps: | |
| - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 | |
| # Standalone mode (no Semgrep AppSec Platform connection, no | |
| # SEMGREP_APP_TOKEN): `semgrep ci` requires that token to actually be | |
| # configured as a repo secret, and fails outright for a fork PR or a | |
| # Dependabot PR either way (GitHub withholds secrets from both for | |
| # security). `p/ci` is the same ruleset pre-commit's own semgrep hook | |
| # already runs locally (see .pre-commit-config.yaml), so CI enforces | |
| # exactly what a contributor's pre-commit run already checked. | |
| - run: semgrep scan --config p/ci --error --skip-unknown-extensions . |