Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add GitHub Action: ShiftLeft NextGen Static Analysis #2

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

robwlundy
Copy link
Owner

ShiftLeft Logo

This pull request adds a GitHub Action workflow file that executes ShiftLeft NextGen SAST (NG SAST) on this PR. Once merged, it will also execute NG SAST on all future PRs opened in this repo.

Visit shiftleft.io to see the security findings for this repository.

We've done a few things on your behalf

  • Forked this demo application and opened a pull request
  • Generated a unique secret SHIFTLEFT_ACCESS_TOKEN to allow GitHub Actions in this repository to communicate with the ShiftLeft API
  • Created a GitHub Action that will send this pull request to ShiftLeft for analysis
  • Added a status check that displays the result of the GitHub Action

Questions? Comments? Want to learn more? Get in touch with us or check out our documentation.

@github-actions
Copy link

ShiftLeft Logo

Summary

ShiftLeft NextGen Static Analysis detected 11 findings in this PR

Severity Count
Critical 3
Moderate 0
Info 2

Aditionally there are 2 secrets leaked.

An additional 4 insights (potential vulnerabilities) require further review.

Build Rules

Build rule with ID "allow-zero-findings" failed because it matched 5 findings and the configured threshold is 0

Get more information about this scan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant