diff --git a/.github/workflows/checkmarx.yml b/.github/workflows/checkmarx.yml deleted file mode 100644 index 5a1ea01..0000000 --- a/.github/workflows/checkmarx.yml +++ /dev/null @@ -1,54 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. - -# This is a basic workflow to help you get started with Using Checkmarx CxFlow Action - -name: CxFlow - -on: - push: - branches: [ main ] - pull_request: - # The branches below must be a subset of the branches above - branches: [ main ] - schedule: - - cron: '21 18 * * 5' - -# A workflow run is made up of one or more jobs that can run sequentially or in parallel - this job is specifically configured to use the Checkmarx CxFlow Action -permissions: - contents: read - -jobs: - # This workflow contains a single job called "build" - build: - # The type of runner that the job will run on - Ubuntu is required as Docker is leveraged for the action - permissions: - contents: read # for actions/checkout to fetch code - issues: write # for checkmarx-ts/checkmarx-cxflow-github-action to write feedback to github issues - pull-requests: write # for checkmarx-ts/checkmarx-cxflow-github-action to write feedback to PR - security-events: write # for github/codeql-action/upload-sarif to upload SARIF results - runs-on: ubuntu-latest - - # Steps require - checkout code, run CxFlow Action, Upload SARIF report (optional) - steps: - # Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it - - uses: actions/checkout@v2 - # Runs the Checkmarx Scan leveraging the latest version of CxFlow - REFER to Action README for list of inputs - - name: Checkmarx CxFlow Action - uses: checkmarx-ts/checkmarx-cxflow-github-action@9975af7d6b957abec9ee9646effa3fb3b82c5314 - with: - project: ${{ secrets.CHECKMARX_PROJECT }} - team: ${{ secrets.CHECKMARX_TEAMS }} - checkmarx_url: ${{ secrets.CHECKMARX_URL }} - checkmarx_username: ${{ secrets.CHECKMARX_USERNAME }} - checkmarx_password: ${{ secrets.CHECKMARX_PASSWORD }} - checkmarx_client_secret: ${{ secrets.CHECKMARX_CLIENT_SECRET }} - scanners: sast - params: --namespace=${{ github.repository_owner }} --repo-name=${{ github.event.repository.name }} --branch=${{ github.ref }} --cx-flow.filterSeverity --cx-flow.filterCategory - # Upload the Report for CodeQL/Security Alerts - - name: Upload SARIF file - uses: github/codeql-action/upload-sarif@v1 - with: - sarif_file: cx.sarif