From 6f267bbe29513cee9c59a748775852e46bc40196 Mon Sep 17 00:00:00 2001 From: LRVT <21357789+l4rm4nd@users.noreply.github.com> Date: Thu, 25 Jul 2024 14:53:55 +0200 Subject: [PATCH] chore(ci): add bandit sast scanning --- .github/workflows/docker-image.yml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index f8b216a..a30f43b 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -42,6 +42,27 @@ jobs: body: ${{ steps.changelog.outputs.clean_changelog }} token: ${{ secrets.GITHUB_TOKEN }} + bandit: + name: SAST with Bandit + needs: changelog + if: github.event_name != 'pull_request' && needs.changelog.outputs.skipped == 'false' + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Set up Python + uses: actions/setup-python@v4 + with: + python-version: '3.x' + + - name: Install Bandit + run: pip install bandit + + - name: Run Bandit + run: bandit -r linkedindumper.py --severity-level medium + deploy: name: Deploy Image needs: changelog