Skip to content

ci: add Semgrep OSS scanning workflow#7060

Merged
vaishakdinesh merged 1 commit intonextfrom
hrushikesh/add-semgrep-oss-workflow
Apr 24, 2026
Merged

ci: add Semgrep OSS scanning workflow#7060
vaishakdinesh merged 1 commit intonextfrom
hrushikesh/add-semgrep-oss-workflow

Conversation

@hrushikeshdeshpande
Copy link
Copy Markdown

Summary

Adds Semgrep Community Edition (OSS) scanning to this repository as part of the App&ProdSec team's migration from Semgrep Pro to Semgrep CE.

What it does

  • Runs on every PR, on push to the main/master branch, and monthly on a staggered schedule.
  • Uses actions/cache@v5 so pip install semgrep only runs on cold cache (first run, version bump, or 7-day idle).
  • Pinned to semgrep==1.160.0 with --config=auto (default OSS ruleset).
  • Runs on ubuntu-slim with contents: read token scope.

For reviewers

  • Findings are informational; the job does not block on findings.
  • First PR after merge installs Semgrep; subsequent PRs skip that step.

See the internal App&ProdSec email for migration context, or ping us internally.

@hrushikeshdeshpande hrushikeshdeshpande requested a review from a team as a code owner April 24, 2026 00:49
@vaishakdinesh vaishakdinesh changed the base branch from main to next April 24, 2026 03:59
@vaishakdinesh vaishakdinesh merged commit ce03ffa into next Apr 24, 2026
9 checks passed
@vaishakdinesh vaishakdinesh deleted the hrushikesh/add-semgrep-oss-workflow branch April 24, 2026 04:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants