diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index aad9bf21..60421cbc 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -54,9 +54,6 @@ workflows: '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': - 'actions/checkout@v7.0.1' - '.github/workflows/semgrep.yml': - - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' '.github/workflows/spark-theatre-gate.yml': [] '.github/workflows/stdlib-naming.yml': - 'actions/checkout@v7.0.1' diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml deleted file mode 100644 index a863a658..00000000 --- a/.github/workflows/semgrep.yml +++ /dev/null @@ -1,37 +0,0 @@ -# This workflow is managed by gh actions-lock. -# SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. -name: Semgrep SAST -on: - push: - branches: [main] - pull_request: - branches: [main] - schedule: - - cron: '0 5 * * 1' - workflow_dispatch: -permissions: read-all -# Actions concurrency pool. Applied only to read-only check workflows -# (no publish/mutation), so cancelling a superseded run is always safe. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true -jobs: - semgrep: - runs-on: ubuntu-latest - timeout-minutes: 10 - permissions: - security-events: write - contents: read - container: - image: semgrep/semgrep - steps: - - uses: actions/checkout@v7.0.1 - - name: Run Semgrep - run: semgrep scan --sarif --output=semgrep.sarif --config=auto . - - name: Upload SARIF - uses: github/codeql-action/upload-sarif@v4.38.2 - with: - sarif_file: semgrep.sarif - if: always()