--- /dev/null
+# This workflow integrates njsscan with GitHub's Code Scanning feature
+# nodejsscan is a static security code scanner that finds insecure code patterns in your Node.js applications
+
+name: njsscan sarif
+
+on:
+ push:
+ branches: [ develop ]
+ pull_request:
+ # The branches below must be a subset of the branches above
+ branches: [ develop ]
+ schedule:
+ - cron: '15 0 * * 5'
+
+jobs:
+ njsscan:
+ runs-on: ubuntu-latest
+ name: njsscan code scanning
+ steps:
+ - name: Checkout the code
+ uses: actions/checkout@v2
+ - name: nodejsscan scan
+ id: njsscan
+ uses: ajinabraham/njsscan-action@master
+ with:
+ args: '. --sarif --output results.sarif || true'
+ - name: Upload njsscan report
+ uses: github/codeql-action/upload-sarif@v1
+ with:
+ sarif_file: results.sarif