Open mikhail-khodorovskiy opened 1 year ago
I was having the same issue, so I install clj-holmes manually for debugging it. When scanning it, a parsing error arises, causing clj-holmes not triggering anything (it would be useful failing the scan step if parsing issues are detected).
Additionally, the sarif file rules field only contains the rules detected in your code. In other words, if the rules provided doesn't match anything in your code then nothing will be shown in the rules field (I intentionally introduced https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/clojure-weak-ssl-context/weak_context.clj to test it out)
No rules seem to be used when the default rules database is used.
Action setup:
The results don't show the rules used and as a result the are no violations found.