Add Debricked starter workflow (#2107)

* Add Debricked starter workflow

* Add permissions section

* Remove schedule

* Fix review comments

---------

Co-authored-by: Alexis Abril <[email protected]>
This commit is contained in:
Michael Chernov
2024-08-16 10:16:20 -05:00
committed by GitHub
co-authored by Alexis Abril
parent af1bbdc430
commit 83b6e98d43
3 changed files with 65 additions and 0 deletions
+43
View File
@@ -0,0 +1,43 @@
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
# documentation.
#####################################################################################################################################################################
# Use this workflow template as a basis for integrating Debricked into your GitHub workflows. #
# #
# If you need additional assistance with configuration feel free to contact us via chat or email at [email protected] #
# To learn more about Debricked or contact our team, visit https://debricked.com/ #
# #
# To run this workflow, complete the following set-up steps: #
# #
# 1. If you dont have a Debricked account, create one by visiting https://debricked.com/app/en/register #
# 2. Generate your Debricked access token, by following the steps mentioned in https://portal.debricked.com/administration-47/how-do-i-generate-an-access-token-130 #
# 3. In GitHub, navigate to the repository #
# 4. Click on “Settings” (If you cannot see the “Settings” tab, select the dropdown menu, then click “Settings”) #
# 5. In the “Security” section click on “Secrets and variables”, then click “Actions” #
# 6. In the “Secrets” tab, click on “New repository secret” #
# 7. In the “Name” field, type the name of the secret #
# 8. In the “Secret” field, enter the value of the secret #
# 9. Click “Add secret” #
# 10. You should now be ready to use the workflow! #
#####################################################################################################################################################################
name: Debricked Scan
on:
push:
permissions:
contents: read
jobs:
vulnerabilities-scan:
name: Vulnerabilities scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: debricked/actions@v3
env:
DEBRICKED_TOKEN: ${{ secrets.DEBRICKED_TOKEN }}
@@ -0,0 +1,19 @@
{
"name": "Debricked Scan",
"creator": "OpenText",
"description": "Integrate with Debricked's state of the art AI-powered Software Composition Analysis to automate your security.",
"iconName": "debricked",
"categories": [
"Code Scanning",
"Python",
"JavaScript",
"Java",
"PHP",
"Ruby",
"Go",
"Rust",
"Swift",
"C#",
"Objective-C"
]
}