Skip to content

Add security workflows#6

Merged
maxammann merged 40 commits intomainfrom
security
Dec 2, 2025
Merged

Add security workflows#6
maxammann merged 40 commits intomainfrom
security

Conversation

@maxammann
Copy link
Contributor

@maxammann maxammann commented Nov 27, 2025

adds/updates for PRs:

  • zizmor
  • semgrep

adds on main pushes:

  • report dependencies to dependency-track
  • zizmor and report to DefectDojo
  • semgrep and report to DefectDojo
  • scorecard and report to DefectDojo

@github-advanced-security
Copy link
Contributor

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Comment on lines +20 to +22
- uses: actions/checkout@v3
with:
fetch-depth: 0

Check warning

Code scanning / zizmor

credential persistence through GitHub Actions artifacts

credential persistence through GitHub Actions artifacts
@KittyCAD KittyCAD deleted a comment from graphite-app bot Nov 28, 2025
@maxammann maxammann merged commit 6fd5ac0 into main Dec 2, 2025
6 checks passed
@maxammann maxammann deleted the security branch December 2, 2025 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants