Closed pritchyspritch closed 3 months ago
Added documentation for GitHub Compliance App, and logic to allow semgrep in case repo is private or developer preference.
v1 of this workflow would not have worked for private repos due to licensing issues.
This version includes:
Successful run on test repo, shows build breaking due to security issues found outside of SLA policies: https://github.com/DFE-Digital/test-codeql/actions/runs/9909251763
Devops
Added documentation for GitHub Compliance App, and logic to allow semgrep in case repo is private or developer preference.
Context
v1 of this workflow would not have worked for private repos due to licensing issues.
Changes proposed in this pull request
This version includes:
Guidance to review
Successful run on test repo, shows build breaking due to security issues found outside of SLA policies: https://github.com/DFE-Digital/test-codeql/actions/runs/9909251763
Checklist
Devops
label