Skip to content

Update workflow actions to latest versions for improved security and … #2

Update workflow actions to latest versions for improved security and …

Update workflow actions to latest versions for improved security and … #2

Workflow file for this run

# ESLint is a tool for identifying and reporting on patterns found in ECMAScript/JavaScript code.
# More details at https://github.com/eslint/eslint and https://eslint.org
name: "SAST - ESLint"
on:
push:
branches: [ "main" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "main" ]
schedule:
- cron: '39 9 * * 4'
jobs:
eslint:
name: Run eslint scanning
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
steps:
- name: Checkout code
uses: actions/checkout@de0fac28217160c9e1c4a3e79f4436864c564dc7 # v6.0.2
- name: Install ESLint
run: |
npm install eslint@8.10.0
npm install @microsoft/eslint-formatter-sarif@3.1.0
- name: Run ESLint
env:
SARIF_ESLINT_IGNORE_SUPPRESSED: "true"
run: npx eslint .
--config .eslintrc.js
--ext .js,.jsx,.ts,.tsx
--format @microsoft/eslint-formatter-sarif
--output-file eslint-results.sarif
continue-on-error: true
- name: Upload analysis results to GitHub
uses: github/codeql-action/upload-sarif@d4b3ca94f14f5cf92f51e5f8efe83e46c6c46ad1 # v4.1.3
with:
sarif_file: eslint-results.sarif
wait-for-processing: true