Skip to content

Bump anchore/sbom-action from 0.20.5 to 0.24.0 #9

Bump anchore/sbom-action from 0.20.5 to 0.24.0

Bump anchore/sbom-action from 0.20.5 to 0.24.0 #9

Workflow file for this run

# ESLint is a tool for identifying and reporting on patterns found in ECMAScript/JavaScript code.
# More details at https://github.com/eslint/eslint and https://eslint.org
name: "SAST - ESLint"
on:
push:
branches: [ "main" ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ "main" ]
schedule:
- cron: '39 9 * * 4'
jobs:
eslint:
name: Run eslint scanning
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Install ESLint
run: |
npm install eslint@8.10.0
npm install @microsoft/eslint-formatter-sarif@3.1.0
- name: Run ESLint
env:
SARIF_ESLINT_IGNORE_SUPPRESSED: "true"
working-directory: src/webapp01
run: npx eslint .
--config .eslintrc.js
--ext .js,.jsx,.ts,.tsx
--format @microsoft/eslint-formatter-sarif
--output-file eslint-results.sarif
continue-on-error: true
- name: Upload analysis results to GitHub
uses: github/codeql-action/upload-sarif@0e9f55954318745b37b7933c693bc093f7336125 # v4.35.1
with:
sarif_file: src/webapp01/eslint-results.sarif
wait-for-processing: true