From 43e69291dfb8d3a80c9212849c7374b98f279058 Mon Sep 17 00:00:00 2001 From: George Petrakis Date: Fri, 20 Dec 2024 09:33:18 +0200 Subject: [PATCH] Feat: enhance build workflow to upload SARIF results from Golang Security Scanner --- .github/workflows/build&test.yaml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build&test.yaml b/.github/workflows/build&test.yaml index 8a8f82d..94ff337 100644 --- a/.github/workflows/build&test.yaml +++ b/.github/workflows/build&test.yaml @@ -98,7 +98,12 @@ jobs: - name: 🔍 Run Golang Security Scanner uses: securego/gosec@v2.21.4 with: - args: ./... + args: '-no-fail -fmt sarif -out results.sarif ./...' + + - name: 📝 Upload SARIF Results + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: results.sarif - name: 🌐 Set Up Node.js uses: actions/setup-node@v4